OpenID Connect (OIDC) / OAuth 2.0 authentication overview
OpsCenter supports user authentication through OpenID Connect (OIDC) and OAuth 2.0 identity providers (IdPs).
When you enable OIDC authentication, OpsCenter delegates identity verification to your central identity provider, such as Okta or Microsoft Entra ID. OpsCenter receives cryptographically signed tokens from the IdP and maps user claims and group memberships to OpsCenter roles.
Key capabilities
- Single sign-on (SSO)
-
Web users authenticate through your identity provider using the standard OAuth 2.0 Authorization Code flow with Proof Key for Code Exchange (PKCE).
- API and automation access
-
Scripts, CI/CD pipelines, and automated tools authenticate to OpsCenter REST APIs using standard JSON Web Token (JWT) bearer tokens sent in the HTTP
Authorization: Bearer JWT_ACCESS_TOKENheader. - Automatic discovery
-
When you configure the identity provider
issuerURL, OpsCenter automatically discovers all required IdP endpoints from the standard OIDC discovery document (.well-known/openid-configuration). - Cryptographic token validation
-
OpsCenter fetches the provider JSON Web Key Set (JWKS) at startup, caches keys in memory, and validates token signatures, expiration timestamps, audience, and issuer on every request.
- Role and permission mapping
-
OpsCenter extracts user group memberships from configured token claims and maps them to OpsCenter roles with corresponding permissions. When a user logs in, OpsCenter resolves user permissions by evaluating claims in the token:
-
OpsCenter inspects the claim specified in
roles_claim(default:groups). -
If explicit mappings are configured in
groups_to_roles(for example,/opscenter-admin → admin), OpsCenter maps matching IdP groups to the specified OpsCenter roles. -
If any value in the user’s role claim matches a name listed in
admin_group_name, OpsCenter grants the user the built-inadminrole. -
For all other values in the role claim, OpsCenter searches for an existing OpsCenter role with the same name and grants that role to the user.
-
If a user belongs to multiple groups mapped to different roles, OpsCenter merges permissions across all assigned roles.
-
OpsCenter OIDC authentication flow
OpsCenter OIDC authentication applies to the web UI and API access.
Web UI access is handled through interactive user login with PKCE protection:
-
A user navigates to the OpsCenter web UI.
-
OpsCenter creates a cryptographically random code verifier, generates a code challenge, and redirects the browser to the IdP authorization endpoint.
-
The user enters their credentials at the IdP login page.
-
The IdP redirects the browser back to OpsCenter at
/auth/oidc/callbackwith an authorization code. -
OpsCenter sends the authorization code and the original code verifier to the IdP token endpoint.
-
The IdP verifies the code challenge and returns an ID token and access token.
-
OpsCenter validates the token signatures against the IdP JWKS keys, resolves user roles from the token claims, and creates an encrypted session cookie.
API access is handled through JWT tokens. For an explanation of this process, see Access the REST API with bearer tokens.