Home / Companies / Octopus Deploy / Blog / Post Details
Content Deep Dive

Configuring generic OIDC provider for authentication

Blog post from Octopus Deploy

Post Details
Company
Date Published
Author
Shawn Sesna
Word Count
1,155
Company Posts That Month
3
Language
English
Hacker News Points
-
Post removed?
No
Summary

Octopus Deploy can use Auth0 as a generic OpenID Connect provider to authenticate users, requiring an Auth0 Regular Web Application configured with Octopus callback and optional logout URLs, followed by entering Auth0’s domain, client ID, and client secret in Octopus’s OpenID Connect settings. The configuration can optionally enable automatic user creation and uses the name claim for usernames. Because Auth0 does not automatically include roles in OIDC tokens, administrators must create Auth0 roles, assign users to them, and add a post-login Auth0 Action that inserts role memberships as a namespaced custom claim in the ID token. Octopus Deploy is then configured to use that custom claim as its role claim type, allowing Auth0 roles to be mapped to Octopus Teams and their associated permissions without adding individual users. For troubleshooting, the post recommends temporarily using jwt.io as an allowed callback URL and initiating an Auth0 authorization request to inspect the decoded token and verify that the expected roles claim is present.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.