OpenCloud
Sign in to OpenCloud with Pocket ID.
OpenCloud ships with a built-in identity provider (IDP), but it can be replaced with an external OIDC provider. This guide walks through replacing the internal IDP with Pocket ID.
Replace opencloud.example.com with the domain of your OpenCloud instance and id.example.com with the domain of your Pocket ID instance.
Key requirements
Section titled “Key requirements”OpenCloud enforces a few constraints on external OIDC providers:
- All clients must be public clients using PKCE (Authorization Code + PKCE flow). There are no confidential clients.
- Desktop and mobile clients use predefined, hardcoded
client_idvalues (OpenCloudDesktop,OpenCloudAndroid,OpenCloudIOS). These must be registered in Pocket ID with those exact IDs; see Create the desktop and mobile clients. - The provider must include a role claim in the access token.
OpenCloud maps claim values to its internal roles (
opencloudAdmin,opencloudSpaceAdmin,opencloudUser,opencloudGuest).
Create groups in Pocket ID
Section titled “Create groups in Pocket ID”In Pocket ID, open Administration → User Groups and click Add Group to create the following four groups. They are used both for access control and role assignment.
| Name | Purpose |
|---|---|
opencloud_admins |
Maps to the opencloudAdmin role |
opencloud_spaceadmins |
Maps to the opencloudSpaceAdmin role |
opencloud_users |
Maps to the opencloudUser role |
opencloud_guests |
Maps to the opencloudGuest role |
After creating each group, open it and go to Custom Claims.
Add a claim with the key opencloud_role and the value from the table below:
| Group | Claim key | Claim value |
|---|---|---|
opencloud_admins |
opencloud_role |
opencloudAdmin |
opencloud_spaceadmins |
opencloud_role |
opencloudSpaceAdmin |
opencloud_users |
opencloud_role |
opencloudUser |
opencloud_guests |
opencloud_role |
opencloudGuest |
Every user must belong to at least one of these groups. Users without a group can authenticate but receive an error inside OpenCloud.
Create the client in Pocket ID
Section titled “Create the client in Pocket ID”This is the client for the OpenCloud web frontend.
- In Pocket ID, open Administration → OIDC Clients and click Add OIDC Client.
- Enter a name such as
OpenCloud, choose Public Client as the client type and add the callback URLs:https://opencloud.example.com/https://opencloud.example.com/oidc-callback.htmlhttps://opencloud.example.com/oidc-silent-redirect.html - Click Create and copy the Client ID (a UUID). You need it to configure OpenCloud.
- On the client’s General tab, add
https://opencloud.example.comunder Logout Callback URLs, turn on PKCE and save. - On the client’s Access tab, select the four OpenCloud groups under Allowed User Groups.
No client secret is needed.
OpenCloud’s web frontend is a public SPA and never sends a client_secret.
Create the desktop and mobile clients
Section titled “Create the desktop and mobile clients”OpenCloud’s desktop and mobile clients send hardcoded client_id values that can’t be changed in the application.
You must register clients in Pocket ID with those exact IDs instead of the auto-generated UUID.
Desktop
Section titled “Desktop”- In Pocket ID, open Administration → OIDC Clients and click Add OIDC Client.
- Enter a name such as
OpenCloud Desktop, choose Public Client as the client type and add the callback URLs:http://127.0.0.1http://localhost - Click Set custom client ID and enter
OpenCloudDesktop. - Click Create.
- On the client’s General tab, turn on PKCE and save.
- On the client’s Access tab, select the four OpenCloud groups under Allowed User Groups.
Android
Section titled “Android”- In Pocket ID, open Administration → OIDC Clients and click Add OIDC Client.
- Enter a name such as
OpenCloud Android, choose Public Client as the client type and add the callback URLoc://android.opencloud.eu. - Click Set custom client ID and enter
OpenCloudAndroid. - Click Create.
- On the client’s General tab, turn on PKCE and save.
- On the client’s Access tab, select the four OpenCloud groups under Allowed User Groups.
- In Pocket ID, open Administration → OIDC Clients and click Add OIDC Client.
- Enter a name such as
OpenCloud iOS, choose Public Client as the client type and add the callback URLoc://ios.opencloud.eu. - Click Set custom client ID and enter
OpenCloudIOS. - Click Create.
- On the client’s General tab, turn on PKCE and save.
- On the client’s Access tab, select the four OpenCloud groups under Allowed User Groups.
Configure OpenCloud
Section titled “Configure OpenCloud”Set the following environment variables on your OpenCloud deployment.
Replace id.example.com with your Pocket ID domain and <client-id> with the Client ID of the web frontend client.
# Disable the built-in IDPOC_EXCLUDE_RUN_SERVICES=idp
# External OIDC issuerOC_OIDC_ISSUER=https://id.example.comPROXY_OIDC_ISSUER=https://id.example.com
# Web frontend client (Client ID of the web frontend client)WEB_OIDC_CLIENT_ID=<client-id>WEB_OIDC_AUTHORITY=https://id.example.comWEB_OIDC_METADATA_URL=https://id.example.com/.well-known/openid-configurationWEB_OIDC_RESPONSE_TYPE=codeWEB_OIDC_SCOPE=openid profile email groups
# Proxy OIDC settingsPROXY_OIDC_CLIENT_ID=<client-id>PROXY_OIDC_REWRITE_WELLKNOWN=truePROXY_OIDC_ACCESS_TOKEN_VERIFY_METHOD=none
# User auto-provisioningPROXY_AUTOPROVISION_ACCOUNTS=truePROXY_AUTOPROVISION_CLAIM_USERNAME=preferred_usernamePROXY_AUTOPROVISION_CLAIM_EMAIL=emailPROXY_AUTOPROVISION_CLAIM_DISPLAYNAME=namePROXY_AUTOPROVISION_CLAIM_GROUPS=groups
# User identity mappingPROXY_USER_OIDC_CLAIM=preferred_usernamePROXY_USER_CS3_CLAIM=username
# Role assignment — reads the opencloud_role custom claim set on Pocket ID groupsPROXY_ROLE_ASSIGNMENT_DRIVER=oidcPROXY_ROLE_ASSIGNMENT_OIDC_CLAIM=opencloud_role
# GraphGRAPH_ASSIGN_DEFAULT_USER_ROLE=falseGRAPH_USERNAME_MATCH=noneContent Security Policy
Section titled “Content Security Policy”If you use a CSP config file, allow connections to your Pocket ID instance:
directives: connect-src: - "'self'" - 'https://id.example.com' - 'wss://id.example.com'The WebSocket entry must use
wss://id.example.com, with no trailing slash and no embeddedhttps://prefix.
Troubleshooting
Section titled “Troubleshooting”“Logging you in — Please wait, you are being redirected” (stuck)
Section titled ““Logging you in — Please wait, you are being redirected” (stuck)”The OIDC callback is reached, but the token exchange fails silently.
Verify that the Pocket ID client has both Public Client and PKCE turned on.
A confidential client without PKCE causes the redirect to complete but the code exchange to fail, because the browser never sends a client_secret.
“This could be because of a routine safety log out, or because your account is either inactive or not yet authorized for use”
Section titled ““This could be because of a routine safety log out, or because your account is either inactive or not yet authorized for use””The user authenticated successfully, but OpenCloud couldn’t assign a role. Check:
- The user isn’t in any OpenCloud group: add the user to one of the four groups in Pocket ID.
- The
opencloud_rolecustom claim is missing: verify each group has the claim configured as described in Create groups in Pocket ID. - The claim name doesn’t match: confirm
PROXY_ROLE_ASSIGNMENT_OIDC_CLAIMequalsopencloud_role.
Desktop or mobile client receives “unauthorized_client”
Section titled “Desktop or mobile client receives “unauthorized_client””The predefined client ID (OpenCloudDesktop, OpenCloudAndroid or OpenCloudIOS) doesn’t exist in Pocket ID.
Follow Create the desktop and mobile clients to register it.
Users can sign in but see an empty file list or permission errors
Section titled “Users can sign in but see an empty file list or permission errors”PROXY_USER_OIDC_CLAIM must identify users uniquely and consistently across logins.
preferred_username works well with Pocket ID.
Avoid email if users are allowed to change their email address in Pocket ID.