Skip to main content

OIDC/OAuth2 Configuration

OpenID Connect (OIDC) is an authentication layer built on top of the OAuth 2.0 framework. It enables IQ Server to securely verify the identity of a user via an external OpenID Provider (OP) and obtain basic user profile information.

When OIDC is configured, users are redirected to your organization's OpenID Provider for login, providing a Single Sign-On (SSO) experience.

Enabling the Feature

Before you can configure OIDC, you will need to enable the feature using the Feature Configuration API:

curl -u <username>:<password> -X POST "http://<host>:<port>/api/v2/config/features/OAUTH2_ENABLED"(need to also refresh the UI after enabling) 

Requirements

This configuration requires a user with the System Administrator role.

Before configuring OIDC, you must meet the following prerequisites:

  • Sonatype IQ Server v1.198 or later.

  • You will need to enable the feature using the Feature Configuration API:

    curl -u <username>:<password> -X POST "http://<host>:<port>/api/v2/config/features/OAUTH2_ENABLED"(need to also refresh the UI after enabling) 
  • The Base URL property must be configured in IQ.

  • Access to an OIDC-compliant IdP such as Keycloak, Okta, or Auth0.

  • The following IdP details:

    • Client ID

    • Client Secret

    • Issuer URL

    • Authorization URL

    • Token URL

    • JWKS URL

All communication between IQ and the IdP must use HTTPS.

Configuring OIDC

  1. Log in to IQ as an administrator.

  2. Navigate to System Preferences → OAuth2 Configuration.

  3. Complete the following fields with values from your identity provider:

    Field

    Description

    IdP Issuer

    Base URL of the IdP’s issuer endpoint.

    Client ID

    Application ID registered in the IdP.

    Client Secret

    Secret associated with the client.

    Authorization URL

    URL used to start the authorization flow.

    Token URL

    URL used to exchange the authorization code for tokens.

    JWKS URL

    JSON Web Key Set URL for signature validation

    JWS Algorithm

    Signing algorithm (for example RS256)

    Username Claim

    Claim identifying the user (for example email)

    Groups Claim

    Claim listing the user’s roles or groups

    Email Claim

    Claim containing the user’s email address

    Callback URL (Redirect URI)

    https://<IQ_SERVER_HOST>/oidc/callback

  4. Select Save.

    When the configuration is valid and the OAUTH2_ENABLED feature flag is enabled, a Single Sign-On button appears on the login page.

Configuring through the REST API

For details about the available OIDC configuration endpoints, see OIDC Configuration REST API.