[Feature Request] SSO Support (Authentic / Authelia)
Pretty much feature request title, add ability to perform authentication via SSO in either SAML2 and/or OIDC .
12 Comments
I'm currently working through some edge cases before submitting the PR. I've also pulled in a few community PRs (like SSH terminal access) which needed slight modifications to work with OIDC's cookie-based authentication instead of localStorage tokens.
Planning to submit a clean PR shortly.
Wouldn;t this be a duplicate of #92 then?
I've been working on an OIDC/SSO implementation in my fork and have it running in production with Authentik as the identity provider. The implementation includes:
- Full OIDC authentication flow with PKCE
- Automatic user provisioning from IdP
- Group-to-role mapping (sync admin/user roles from IdP groups)
- Secure token handling via httpOnly cookies
- Database migrations for OIDC fields
I'm currently working through some edge cases before submitting the PR. I've also pulled in a few community PRs (like SSH terminal access) which needed slight modifications to work with OIDC's cookie-based authentication instead of localStorage tokens.
Planning to submit a clean PR shortly.
I am actually working on this in my fork to add OIDC with Authentic. I was going to contribute back when I was done, if I could, as I love helping the community that we all have here.
Hi there,
Also using OIDC as standard in my homelab and will start playing arround with PatchMon very soon.
So +1 for this feature! 😉👌
I use pocket id and its fab.
·10 months agoReally want to do this, this morning I’ve been looking into using clerk for sso authentication.
Using this in my homelab too for every service I deploy (like many other homelabbers). Willing to help if you need any help with OIDC.
also integration with keycloak
Hi @9technologygroup , currently we're not leveraging PatchMon in production as it doesn't have existing support for SSO; we try to only deploy applications that support SSO and/or LDAP.
But I do have it deployed in our development environment, it's 5 of us that have access to the dev and production side.
We leverage Okta for production SSO, and Authentik for dev (since its free and we can self host). Really any OIDC or SAML2 should be usable by almost any provider.
Hi
This is on the roadmap at the moment, I'm going to close this but it's definitely at the forefront of our minds.
So I can understand your setup a bit better, how many users do you have that will use PatchMon and which SSO platform would you want us to integrate into?
right now i am working on OIDC but this could be included as they are different auth parts and configurations
Will
On Sunday, January 04, 2026 03:50 EST, Jonathan Martens @.***> wrote:
jmartens left a comment (PatchMon/PatchMon#159)
I'm currently working through some edge cases before submitting the PR. I've also pulled in a few community PRs (like SSH terminal access) which needed slight modifications to work with OIDC's cookie-based authentication instead of localStorage tokens.
Planning to submit a clean PR shortly.
Wouldn;t this be a duplicate of #92 then?
—
Reply to this email directly, view it on GitHub, or unsubscribe.
You are receiving this because you commented.Message ID: @.>
[ { @.": "http://schema.org", @.": "EmailMessage", "potentialAction": { @.": "ViewAction", "target": "https://github.com/PatchMon/PatchMon/issues/159#issuecomment-3707878525", "url": "https://github.com/PatchMon/PatchMon/issues/159#issuecomment-3707878525", "name": "View Issue" }, "description": "View this Issue on GitHub", "publisher": { @.***": "Organization", "name": "GitHub", "url": "https://github.com" } } ]
William Grzybowski Senior Apple Architect MacJediWizard | (844) MAC-JEDI Email @.*** Phone +1 (973) 446-6556 LinkedIn View Profile Website macjediwizard.com