This guide walks you through the process of configuring Clavister IdAuth Cloud and Nextcloud to establish seamless integration using OpenID Connect between the two systems. To achieve this, you will need to perform specific configuration steps in both Nextcloud and Clavister Cloud Services. The guide uses our example companyShieldIT as<company_name> through the different steps.
Assumptions
The Nextcloud server is on https://mynextcloud.fqdn/, replace with the real hostname of the Nextcloud server.
Clavister IdAuth Cloud Configuration
- Navigate to Add-ons and OpenID Connect Provider
- Click on Add new button and choose the Custom type
- Provide a name for the Relaying Party
- Enter the Redirect URI, https://mynextcloud.fqdn/apps/user_oidc/code
- Save
Nextcloud Configuration
- Install and Enable https://apps.nextcloud.com/apps/user_oidc
- Navigate to Administration and OpenID Connect
- Click on Register Providers +
- Fill in the following Client Configuration
- Identifier - IdAuth Cloud
- Client ID - Copy from the previous created OpenID Connect Provider
- Client Secret - Copy from the previous created OpenID Connect Provider
- Scope - openid
- Fill in the following Attribute mapping
- User ID mapping - sub
- Groups mapping - groups
- Extra attribute mapping
- Display name mapping - sub
- Deselect Use unique user ID
- Select Use group provisioning
Related articles
How to - Using OIDC in Clavister IdAuth Cloud with OneConnect
5 Dec, 2025 sase cloud oidc oneconnect core
5 Dec, 2025 sase cloud oidc oneconnect core
How to - Using OIDC in Clavister IdAuth Cloud with Portainer BE
5 Dec, 2025 sase cloud oidc
5 Dec, 2025 sase cloud oidc
How to - Configure OIDC with Entra ID and NetWall
4 Jul, 2025 core oneconnect oidc
4 Jul, 2025 core oneconnect oidc
Requirements for JWT Token with OIDC Authentication in Clavister
4 Nov, 2024 oidc core authentication
4 Nov, 2024 oidc core authentication
Use Roles in IdAuth Cloud to limit user access to OneConnect
5 Dec, 2025 sase oneconnect core userauth oidc
5 Dec, 2025 sase oneconnect core userauth oidc