Vikunja
Sign in to the Vikunja task manager with Pocket ID.
Replace vikunja.example.com with the URL of your Vikunja instance and id.example.com with the URL of your Pocket ID instance.
Create the client in Pocket ID
Section titled “Create the client in Pocket ID”- In Pocket ID, open Administration → OIDC Clients and click Add OIDC Client.
- Enter a name such as
Vikunjaand add the callback URLhttps://vikunja.example.com/auth/openid/pocketid. - Click Create and copy the Client ID and the Client secret. The client secret is only shown once.
- On the client’s Access tab, select the groups that may sign in under Allowed User Groups, or choose All Users.
Configure Vikunja
Section titled “Configure Vikunja”You can use either a config.yml file or environment variables to configure Vikunja.
In both cases, replace <client-id> and <client-secret> with the Client ID and the Client secret from Pocket ID.
Using config.yml
Section titled “Using config.yml”This uses the Vikunja 1.0+ syntax. For the deprecated pre-1.0 syntax, see the Vikunja OpenID documentation.
- Map a config file to your Vikunja container, see Using a config file with Docker Compose.
- Add or set the following content in the
config.ymlfile:auth:openid:enabled: trueredirecturl: https://vikunja.example.com/auth/openid/pocketidproviders:PocketID:name: PocketIDauthurl: https://id.example.comclientid: <client-id>clientsecret: <client-secret>scope: openid profile emailforceuserinfo: false # Optional: Set to true to always use UserInfo endpoint instead of ID token claims, defaults to false
Using environment variables
Section titled “Using environment variables”VIKUNJA_AUTH_OPENID_ENABLED: "true"VIKUNJA_AUTH_OPENID_PROVIDERS_POCKETID_AUTHURL: https://id.example.comVIKUNJA_AUTH_OPENID_PROVIDERS_POCKETID_CLIENTID: <client-id>VIKUNJA_AUTH_OPENID_PROVIDERS_POCKETID_CLIENTSECRET: <client-secret>VIKUNJA_AUTH_OPENID_PROVIDERS_POCKETID_NAME: PocketIDVIKUNJA_AUTH_OPENID_PROVIDERS_POCKETID_SCOPE: "openid profile email"Link existing local accounts
Section titled “Link existing local accounts”Vikunja 1.0+ allows users with existing local accounts to log in with OpenID.
This feature links OpenID providers to local user accounts based on matching email and username attributes.
An example config.yml could look like this:
auth: openid: enabled: true redirecturl: https://vikunja.example.com/auth/openid/pocketid providers: PocketID: name: PocketID usernamefallback: true emailfallback: true authurl: https://id.example.com clientid: <client-id> clientsecret: <client-secret> scope: openid profile email forceuserinfo: false # Optional: Set to true to always use UserInfo endpoint instead of ID token claims, defaults to false