[FED-003] Authentik OIDC Integration #86

Closed
opened 2026-01-29 23:29:16 +00:00 by jason.woltje · 0 comments
Owner

Phase 2: Authentik Integration

Integrate Authentik as the identity provider:

  • OIDC provider configuration
  • Token validation and refresh
  • Group-to-role mapping
  • Multi-workspace session handling

Deliverables

  • Authentik setup documentation
  • BetterAuth Authentik adapter (or OIDC generic)
  • Group claim parsing -> role assignment
  • Session isolation per workspace
  • Auth event audit logging

Dependencies

  • #84 Instance Identity Model
  • #83 Federation EPIC
  • Existing BetterAuth setup
## Phase 2: Authentik Integration Integrate Authentik as the identity provider: - OIDC provider configuration - Token validation and refresh - Group-to-role mapping - Multi-workspace session handling ## Deliverables - [ ] Authentik setup documentation - [ ] BetterAuth Authentik adapter (or OIDC generic) - [ ] Group claim parsing -> role assignment - [ ] Session isolation per workspace - [ ] Auth event audit logging ## Dependencies - #84 Instance Identity Model ## Related - #83 Federation EPIC - Existing BetterAuth setup
jason.woltje added this to the M7-Federation (0.0.7) milestone 2026-01-29 23:29:16 +00:00
jason.woltje added the authphase-2apip0api labels 2026-01-29 23:29:16 +00:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: mosaic/stack#86