Kavita
Sign in to the Kavita reading server with Pocket ID.
Create the client in Pocket ID
Section titled “Create the client in Pocket ID”- In Pocket ID, open Administration → OIDC Clients and click Add OIDC Client.
- Enter a name such as
Kavitaand add the callback URLhttps://kavita.example.com/signin-oidc. - Click Create and copy the Client ID and the Client secret. The client secret is only shown once.
- On the client’s General tab, add
https://kavita.example.com/signout-callback-oidcto Logout Callback URLs, then click Save. - On the client’s Access tab, select the groups that may sign in under Allowed User Groups, or choose All Users.
Configure Kavita
Section titled “Configure Kavita”- In Kavita, go to Settings → Server → OpenID Connect.
- Enter your OIDC provider details:
- Authority:
https://id.example.com(no trailing slash) - Client ID: the Client ID from Pocket ID
- Client Secret: the Client secret from Pocket ID
- (Optional) Provider name: Change to
Pocket IDif you wish.
- Authority:
- Save and restart the Kavita server for the settings to take effect. If Require verified emails is enabled in Kavita, turn on Emails verified by default in Pocket ID under Administration → Application Configuration → Email to ensure users can sign in.
- Sign in with the newly added button to test it.
Sync user permissions
Section titled “Sync user permissions”Kavita allows for configuration of user access via synced roles as a custom claim.
- In Pocket ID, open the user (Administration → Users) or the group (Administration → User Groups) that should have access to Kavita.
- Under Custom Claims, add a key-value pair:
- Use a key name that will be unique to Kavita, like
kavita-roles. - Set the value to the roles you wish to give that user.
For multiple roles, format it like this:
[ "Login", "Download", "library-Comics" ]Loginis required to fully sign in to Kavita. Other roles can be found in Kavita’s documentation.- Access to libraries must be granted with
library-<LibraryName>.
- Use a key name that will be unique to Kavita, like
- Save the custom claim in Pocket ID, then sign in to Kavita separately with an admin account.
- In Kavita, go to Settings → Server → OpenID Connect.
- Enable Sync user settings with OIDC roles.
- Scroll down to Advanced Settings and change the Roles claim to the key name you set earlier (
kavita-rolesfor example). - Scroll up and click Save, then restart the Kavita server.
- Sign in to Kavita with a user that has the custom claims applied. It should map the roles on sign-in.
For more information on OIDC settings in Kavita, refer to their documentation.