Synology
Sign in to Synology DSM with Pocket ID.
Replace synology.example.com with the URL of your Synology instance and id.example.com with the URL of your Pocket ID instance.
Create the client in Pocket ID
Section titled “Create the client in Pocket ID”- In Pocket ID, open Administration → OIDC Clients and click Add OIDC Client.
- Enter a name such as
Synologyand add the callback URLhttps://synology.example.com/. - Click Create and copy the Client ID, the Client secret and the OIDC Discovery URL. The client secret is only shown once.
- On the client’s Access tab, select the groups that may sign in under Allowed User Groups, or choose All Users.
Configure Synology
Section titled “Configure Synology”- Open the Synology DSM web interface and open Control Panel.
- Choose Domain/LDAP on the left side, then choose the SSO Client tab at the top.
- Below the Services heading, check Enable OpenID Connect SSO service.
- Click OpenID Connect SSO Settings to open the configuration dialog.
- Set Profile to
OIDC. - Set Account type to
Domain/LDAP/local. - Set Name to
PocketID. - Paste the OIDC Discovery URL from Pocket ID into the Well-known URL field.
- Paste the Client ID from Pocket ID into the Application ID field.
- Paste the Client secret from Pocket ID into the Application secret field.
- Set Redirect URL to
https://synology.example.com. - Set Authorization scope to
openid email profile. - Set Username claim to
preferred_username. This uses the user’s username instead of the email. If the Pocket ID username matches the local Synology DSM account name, the user signs in as the existing user. - Click Save.
- Click Apply on the Control Panel page.
- Sign out and sign back in to test it. The login page now has an SSO Authentication tab that lets you Continue with PocketID.