Pangolin
Sign in to Pangolin with Pocket ID.
Create the client in Pocket ID
Section titled “Create the client in Pocket ID”- In Pocket ID, open Administration → OIDC Clients and click Add OIDC Client.
- Enter a name such as
Pangolinand add the callback URLhttps://pangolin.example.com/auth/idp/<identity-provider-id>/oidc/callback. - Click Create and copy the Client ID and the Client secret. Under Show more details, also copy the Authorization URL and the Token URL. The client secret is only shown once.
- On the client’s Access tab, select the groups that may sign in under Allowed User Groups, or choose All Users.
Pangolin shows the ID for <identity-provider-id> only after you create the identity provider, so you update the callback URL later.
Configure Pangolin
Section titled “Configure Pangolin”- Sign in to Pangolin with your superuser account.
- Under Server Admin, select Identity Providers, then Add Identity Provider.
- Fill in the fields:
- Identity Provider
- Name:
Pocket ID(or anything you want) - Enable Auto Provision Users (only if you want auto provisioning)
- Name:
- Provider Type: select OAuth2/OIDC.
- OAuth2/OIDC Configuration
- Client ID: the Client ID from Pocket ID.
- Client Secret: the Client secret from Pocket ID.
- Authorization URL: the Authorization URL from Pocket ID.
- Token URL: the Token URL from Pocket ID.
- Token Configuration
- Identifier Path: one of
email,preferred_usernameorsub(Advanced) - Email Path:
email - Name Path:
name - Scopes:
openid profile email(includegroupsfor auto provisioning)
- Identifier Path: one of
- Identity Provider
- Save the new identity provider.
- Copy the Redirect URL shown by Pangolin and update the callback URL of the client in Pocket ID so that the two values match exactly.
Create users
Section titled “Create users”Create users either with auto provisioning or manually. Once you have created a user, sign out of Pangolin and sign in with Pocket ID to test it.
Auto provisioning
Section titled “Auto provisioning”See Pangolin’s docs on auto provisioning for more advanced setups.
- In Pocket ID, open Administration → User Groups, click Add Group and create a group:
- Friendly Name:
Admin(or anything you want) - Name:
admin(or anything you want)
- Friendly Name:
- Add the desired admin users to the group.
- In Pangolin, under Server Admin → Identity Providers, edit the Pocket ID provider and make sure Auto Provision Users is enabled and the Scopes include
groups. - Open Organization Policies.
- Under Default Mappings, set:
- Default Role Mapping:
contains(groups, 'admin') && 'Admin' || 'Member'(replaceadminwith the name of your user group) - Default Organization Mapping:
'YOUR PANGOLIN ORGANIZATION ID'(see the examples of advanced mappings in Pangolin’s docs)
- Default Role Mapping:
- Click Save Default Mappings.
Manually
Section titled “Manually”- In Pangolin, go to your organization, select Users, then Create User.
- Select External User, select your Pocket ID identity provider and fill in the relevant details.
Enter the value that matches your Identifier Path in the Username field:
emailis your Pocket ID email.preferred_usernameis your Pocket ID username.
Troubleshooting
Section titled “Troubleshooting”User not provisioned (Manual) in the system
Section titled “User not provisioned (Manual) in the system”Make sure you have created a user in Pangolin and that its Username matches the Identifier Path used.
After signing in with OIDC (auto provisioned): There was a problem connecting to Pocket ID. Please contact your administrator.
Section titled “After signing in with OIDC (auto provisioned): There was a problem connecting to Pocket ID. Please contact your administrator.”In Pangolin, under Server Admin → Identity Providers, edit the Pocket ID provider and make sure the Scopes include groups.
Invalid callback URL, it might be necessary for an admin to fix this
Section titled “Invalid callback URL, it might be necessary for an admin to fix this”The callback URL isn’t set correctly in Pocket ID.
Make sure it matches the Redirect URL in your Pangolin OIDC configuration, for example https://pangolin.example.com/auth/idp/1/oidc/callback.