English | δΈζ
verdaccio-openid adds OpenID Connect login to Verdaccio for both the web UI and the CLI.
- Verdaccio 5, 6, 7
- Node >= 20.19.0
- Browsers that support ES6
npm install -g verdaccio-openidmkdir -p ./install-here/
npm install --global-style \
--bin-links=false --save=false --package-lock=false \
--omit=dev --omit=optional --omit=peer \
--prefix ./install-here/ \
verdaccio-openid@latest
mv ./install-here/node_modules/verdaccio-openid/ /path/to/verdaccio/plugins/Add this to your Verdaccio config:
middlewares:
openid:
enabled: true
auth:
openid:
provider-host: https://example.com
client-id: CLIENT_ID
client-secret: CLIENT_SECRET
username-claim: name
# scope: openid email groups
# groups-claim: groups
# provider-type: gitlab
# store-type: file
# store-config: ./store
# authorized-groups:
# - access
# group-users:
# animal:
# - tom
# - jack| Config key | Description |
|---|---|
provider-host |
The host of the OIDC provider. |
client-id |
The client ID from the OIDC provider. |
client-secret |
The client secret from the OIDC provider. |
See Configuration for the full option list.
Configure these in your OIDC provider:
| Flow | Callback URL |
|---|---|
| Web Authn | https://your-registry.com/-/oauth/callback/authn |
| Web UI | https://your-registry.com/-/oauth/callback |
| CLI | https://your-registry.com/-/oauth/callback/cli |
After setup, clicking the login button sends the user to the OIDC provider.
If auth.htpasswd.file is configured, the login dialog shows first with username and password fields, and the OIDC login button appears below it so users can choose either method.
Set keep-passwd-login explicitly to override the automatic behavior. See keep-passwd-login for details.
npm login --registry http://your-registry.comThis opens a browser window for OIDC login and saves the token automatically.
Note: npm v9+ uses
--auth-type=webby default. For npm v8.14 to v8.x, add--auth-type=webexplicitly. For npm older than v8.14, use the legacy flow:npm login --auth-type=legacy --registry http://your-registry.comSee the npm docs for details.
npx verdaccio-openid@latest --registry http://your-registry.comThis uses a local callback server to receive the token. It falls back to this flow when Web Authn is unavailable, such as on older npm versions. See CLI Authentication for legacy login options.
Choose a backend for session state and cache storage:
| Type | Best for |
|---|---|
in-memory (default) |
Single-process development |
redis |
Multi-replica deployments |
file |
Single-node persistent storage |
dynamodb |
Cloud-native multi-replica deployments |
mongodb |
Multi-replica setups with MongoDB |
See Store Configuration for setup instructions and peer dependency requirements.
Most config values can be set through environment variables, which is useful when you want to keep secrets out of the config file. See Environment Variables for the naming rules and dotenv support.
See Development for build steps, tests, and project structure.
- Configuration β full config reference and provider discovery
- Store Configuration β Redis, file, DynamoDB, and MongoDB backends
- Environment Variables β env var names and dotenv support
- CLI Authentication β CLI login flow
- Development β build, testing, and project structure
MIT
