How to - Using OIDC in Clavister IdAuth Cloud with Portainer BE

Last modified on 5 Dec, 2025. Revision 4
Up to date for
Clavister Cloud Services 3.9.0
Status OK
Subscription Required
Clavister IdAuth Cloud with Essentials or higher


This guide walks you through the process of configuring Clavister IdAuth Cloud and Portainer to establish seamless integration using OpenID Connect between the two systems. To achieve this, you will need to perform specific configuration steps in both Portainer and Clavister Cloud Services. The guide uses our example companyShieldIT as<company_name> through the different steps.

Assumptions

The Nextcloud server is on https://portainer.fqdn:9443/, replace with the real hostname of the Portainer server.

Clavister IdAuth Cloud Configuration

  1. Navigate to Add-ons and OpenID Connect Provider
  2. Click on Add new button and choose the Custom type
  3. Provide a name for the Relaying Party
  4. Enter the Redirect URI, https://portainer.fqdn:9443/
  5. Save

Portainer Configuration

  1. Navigate to Settings and Authentication
  2. Select OAuth
  3. Enable Automatic user provisioning 
  4. Enable Automatic team provisioning
    1. Claim name - groups
    2. Enable Assign admin rights to group(s) - the Role in IdAuth Cloud that should give admin rights
  5. Select Custom OAuth provider and fill in the following OAuth Configuration
    1. Client ID - Copy from the previous created OpenID Connect Provider
    2. Client secret - Copy from the previous created OpenID Connect Provider
    3. Authorization URL - https://iam.shieldit.sase.eu/authentication/oidc/oidc/login
    4. Access token URL - https://iam.shieldit.sase.eu/authentication/oidc/oidc/token
    5. Resource URL - https://iam.shieldit.sase.eu/authentication/oidc/oidc/userinfo
    6. Redirect URL - https://portainer.fqdn:9443/
    7. Logout URL - https://iam.shieldit.sase.eu/authentication/oidc/oidc/logout
    8. User identifier - sub
    9. Scopes - openid
    10. Auth Style - Auth Decect
  6. Save settings

Related articles

How to - Using OIDC in Clavister IdAuth Cloud with OneConnect
5 Dec, 2025 sase cloud oidc oneconnect core
How to - Configure OIDC with Entra ID and NetWall
4 Jul, 2025 core oneconnect oidc
Use Roles in IdAuth Cloud to limit user access to OneConnect
5 Dec, 2025 sase oneconnect core userauth oidc