OpenID Connect (OIDC) / OAuth 2.0 authentication overview

OpsCenter supports user authentication through OpenID Connect (OIDC) and OAuth 2.0 identity providers (IdPs).

When you enable OIDC authentication, OpsCenter delegates identity verification to your central identity provider, such as Okta or Microsoft Entra ID. OpsCenter receives cryptographically signed tokens from the IdP and maps user claims and group memberships to OpsCenter roles.

Key capabilities

Single sign-on (SSO)

Web users authenticate through your identity provider using the standard OAuth 2.0 Authorization Code flow with Proof Key for Code Exchange (PKCE).

API and automation access

Scripts, CI/CD pipelines, and automated tools authenticate to OpsCenter REST APIs using standard JSON Web Token (JWT) bearer tokens sent in the HTTP Authorization: Bearer JWT_ACCESS_TOKEN header.

Automatic discovery

When you configure the identity provider issuer URL, OpsCenter automatically discovers all required IdP endpoints from the standard OIDC discovery document (.well-known/openid-configuration).

Cryptographic token validation

OpsCenter fetches the provider JSON Web Key Set (JWKS) at startup, caches keys in memory, and validates token signatures, expiration timestamps, audience, and issuer on every request.

Role and permission mapping

OpsCenter extracts user group memberships from configured token claims and maps them to OpsCenter roles with corresponding permissions. When a user logs in, OpsCenter resolves user permissions by evaluating claims in the token:

  • OpsCenter inspects the claim specified in roles_claim (default: groups).

  • If explicit mappings are configured in groups_to_roles (for example, /opscenter-admin → admin), OpsCenter maps matching IdP groups to the specified OpsCenter roles.

  • If any value in the user’s role claim matches a name listed in admin_group_name, OpsCenter grants the user the built-in admin role.

  • For all other values in the role claim, OpsCenter searches for an existing OpsCenter role with the same name and grants that role to the user.

  • If a user belongs to multiple groups mapped to different roles, OpsCenter merges permissions across all assigned roles.

OpsCenter OIDC authentication flow

OpsCenter OIDC authentication applies to the web UI and API access.

Web UI access is handled through interactive user login with PKCE protection:

  1. A user navigates to the OpsCenter web UI.

  2. OpsCenter creates a cryptographically random code verifier, generates a code challenge, and redirects the browser to the IdP authorization endpoint.

  3. The user enters their credentials at the IdP login page.

  4. The IdP redirects the browser back to OpsCenter at /auth/oidc/callback with an authorization code.

  5. OpsCenter sends the authorization code and the original code verifier to the IdP token endpoint.

  6. The IdP verifies the code challenge and returns an ID token and access token.

  7. OpsCenter validates the token signatures against the IdP JWKS keys, resolves user roles from the token claims, and creates an encrypted session cookie.

API access is handled through JWT tokens. For an explanation of this process, see Access the REST API with bearer tokens.

Was this helpful?

Give Feedback

How can we improve the documentation?

© Copyright IBM Corporation 2026 | Privacy policy | Terms of use |  Manage Privacy Choices

Apache, Apache Cassandra, Cassandra, Apache Tomcat, Tomcat, Apache Lucene, Apache Solr, Apache Hadoop, Hadoop, Apache Pulsar, Pulsar, Apache Spark, Spark, Apache TinkerPop, TinkerPop, Apache Kafka and Kafka are either registered trademarks or trademarks of the Apache Software Foundation or its subsidiaries in Canada, the United States and/or other countries. Kubernetes is the registered trademark of the Linux Foundation.

General Inquiries: Contact IBM