OIDC/OAuth2 Configuration
OpenID Connect (OIDC) is an authentication layer built on top of the OAuth 2.0 framework. It enables IQ Server to securely verify the identity of a user via an external OpenID Provider (OP) and obtain basic user profile information.
When OIDC is configured, users are redirected to your organization's OpenID Provider for login, providing a Single Sign-On (SSO) experience.
Enabling the Feature
Before you can configure OIDC, you will need to enable the feature using the Feature Configuration API:
curl -u <username>:<password> -X POST "http://<host>:<port>/api/v2/config/features/OAUTH2_ENABLED"(need to also refresh the UI after enabling)
Requirements
This configuration requires a user with the System Administrator role.
Before configuring OIDC, you must meet the following prerequisites:
Sonatype IQ Server v1.198 or later.
You will need to enable the feature using the Feature Configuration API:
curl -u <username>:<password> -X POST "http://<host>:<port>/api/v2/config/features/OAUTH2_ENABLED"(need to also refresh the UI after enabling)
The Base URL property must be configured in IQ.
Access to an OIDC-compliant IdP such as Keycloak, Okta, or Auth0.
The following IdP details:
Client ID
Client Secret
Issuer URL
Authorization URL
Token URL
JWKS URL
All communication between IQ and the IdP must use HTTPS.
Configuring OIDC
Log in to IQ as an administrator.
Navigate to System Preferences → OAuth2 Configuration.
Complete the following fields with values from your identity provider:
Field
Description
IdP Issuer
Base URL of the IdP’s issuer endpoint.
Client ID
Application ID registered in the IdP.
Client Secret
Secret associated with the client.
Authorization URL
URL used to start the authorization flow.
Token URL
URL used to exchange the authorization code for tokens.
JWKS URL
JSON Web Key Set URL for signature validation
JWS Algorithm
Signing algorithm (for example
RS256)Username Claim
Claim identifying the user (for example
email)Groups Claim
Claim listing the user’s roles or groups
Email Claim
Claim containing the user’s email address
Callback URL (Redirect URI)
https://<IQ_SERVER_HOST>/oidc/callbackSelect Save.
When the configuration is valid and the
OAUTH2_ENABLEDfeature flag is enabled, a Single Sign-On button appears on the login page.
Configuring through the REST API
For details about the available OIDC configuration endpoints, see OIDC Configuration REST API.