Nextcloud
Sign in to Nextcloud with Pocket ID.
Nextcloud doesn’t come with OIDC/SSO out of the box, so you need to install a Nextcloud app for it.
There are two main options: nextcloud/user_oidc and pulsejet/nextcloud-oidc-login.
This guide uses nextcloud/user_oidc, because it’s maintained by Nextcloud and is expected to be supported longer.
Replace nextcloud.example.com with the domain of your Nextcloud instance and id.example.com with the domain of your Pocket ID instance.
Create the client in Pocket ID
Section titled “Create the client in Pocket ID”- In Pocket ID, open Administration → OIDC Clients and click Add OIDC Client.
- Enter a name such as
Nextcloud, keep Confidential Client as the client type and add the callback URLhttps://nextcloud.example.com/apps/user_oidc/code. - Click Create and copy the Client ID, the Client secret and the OIDC Discovery URL. Also copy the Logout URL, which is under Show more details. The client secret is only shown once.
- On the client’s General tab, set Back-Channel Logout URL to the address the
user_oidcapp gives you. Usually it’shttps://nextcloud.example.com/apps/user_oidc/backchannel-logout/PocketID, wherePocketIDis the identifier you give the provider in Nextcloud. Consider turning on PKCE, then save. - On the client’s Access tab, select the groups that may sign in under Allowed User Groups, or choose All Users.
Configure Nextcloud
Section titled “Configure Nextcloud”-
Sign in to Nextcloud with your admin account.
-
In the upper right corner, click your profile picture and select Apps.
-
Under Integration, select OpenID Connect user backend and install it.
-
After installing, go to Administration settings → OpenID Connect.
-
Click + and fill in the information as follows:
-
Identifier:
PocketID(suggestion only) -
Client ID: the Client ID from Pocket ID.
-
Client secret: the Client secret from Pocket ID.
-
Discovery endpoint: the OIDC Discovery URL from Pocket ID.
-
Custom end session endpoint: the Logout URL from Pocket ID.
-
Scope:
openid email profile groups -
By default, Nextcloud creates a new user when someone signs in with Pocket ID. If you want to sign in with an existing Nextcloud user, you need to tell Nextcloud how to match Pocket ID users with Nextcloud users. You can either:
-
Match accounts using a custom claim: set User ID mapping to
nextcloud_username.Then, for each user in Pocket ID, add a custom claim under Custom Claims on the user’s page, with the key
nextcloud_usernameand the Nextcloud account name to sign in to as the value. -
If you have turned off Enable Self-Account Editing in the Pocket ID configuration, match accounts using the Pocket ID username directly: set User ID mapping to
preferred_username.If Enable Self-Account Editing is on, Pocket ID users can change their own username and therefore choose the Nextcloud account they sign in to.
-
-
(Optional) Open Extra-Attribute-Mapping and set Avatar-Mapping to
picture. This downloads the profile picture from Pocket ID. -
(Optional) Check Use group provisioning if you want Pocket ID groups to be replicated on Nextcloud.
-
(Optional) If you use groups, you can whitelist them with Group-Whitelist-Regex, for example
^(nextcloud_(admins|users))$. This regex matches both thenextcloud_adminsandnextcloud_usersgroups. If you also enable the next option, User Login only matching Whitelist-Regex, only users in these groups have access. -
Check Use unique user ID and uncheck Send ID token hint on logout.
-
-
After creating the provider, make sure the Backchannel Logout URL and Redirect URI shown by Nextcloud match the Back-Channel Logout URL and the callback URL in Pocket ID.
Sign in on the Nextcloud mobile app
Section titled “Sign in on the Nextcloud mobile app”The Nextcloud app for iOS doesn’t accept passkey input, which creates a small barrier when using Pocket ID.
If you didn’t disable the regular login, you can use your Nextcloud username and password to sign in.
If you disabled the regular login, create a Login Code on your Pocket ID dashboard (id.example.com).
Then open the Nextcloud app and add your Nextcloud URL (nextcloud.example.com).
When the Pocket ID login appears, select Don’t have access to your passkey?, select Login Code and enter the code you created.
Disable the Nextcloud login form
Section titled “Disable the Nextcloud login form”You can disable the built-in login form in two ways, with slightly different outcomes:
-
Hide the login form: in the Nextcloud
config.php, set'hide_login_form' => true. Nextcloud still shows its login page atnextcloud.example.com, but it says “The Nextcloud login form is disabled.” and shows aLogin with PocketIDbutton instead. The login form is only hidden and can still be accessed by appendinglogin?direct=1to the URL:nextcloud.example.com/login?direct=1. -
Remove the login form: run a command with the Nextcloud CLI inside the container. Since there are many containers and platforms, make sure to use the right form for your container and platform.
- Run
occ config:app:set user_oidc allow_multiple_user_backends --value=0. - The built-in login form is no longer available at
nextcloud.example.com, and you’re automatically redirected to sign in with Pocket ID. - This only works if there is a single OIDC provider and no other login methods.
- Run
Troubleshooting
Section titled “Troubleshooting”If you can’t sign in to Nextcloud:
- Using the Nextcloud CLI, reactivate the login form:
occ config:app:set user_oidc allow_multiple_user_backends --value=1. - Remove the current OIDC configuration with
occ user_oidc:provider:delete PocketID. ReplacePocketIDwith the identifier you used, or the one listed byocc user_oidc:provider. - Create a new OIDC connection with the command below.
Make sure to adjust it as appropriate.
-
After the command is run and you can login back to Nextcloud, make sure to adjust the
Scopeand -
Run:
Terminal window occ user_oidc:provider PocketID \--clientid="<client-id>" \--clientsecret="<client-secret>" \--discoveryuri="https://id.example.com/.well-known/openid-configuration" \--mapping-uid="preferred_username" \--unique-uid=1 \--send-id-token-hint=0Replace
PocketID,<client-id>,<client-secret>and the discovery URL with your identifier and the Client ID, Client secret and OIDC Discovery URL from Pocket ID.
-