Replies: 2 comments 3 replies
|
For Keycloak SSO with Langfuse, there are specific configuration options and known data handling requirements you should be aware of. Keycloak ConfigurationFor Keycloak, Langfuse supports the following environment variables(1):
The OAuth Redirect URL should be Known Keycloak Data HandlingThe Langfuse authentication code includes specific handling for Keycloak responses. When linking an account, the code removes incompatible fields returned by Keycloak(2): // Keycloak returns incompatible data with the nextjs-auth schema
// (refresh_expires_in and not-before-policy in).
// So, we need to remove this data from the payload before linking an account.
// https://github.com/nextauthjs/next-auth/issues/7655
if (data.provider.endsWith("keycloak")) {
// endsWith required as the multi-tenant cloud SSO providers are in the "domain.provider" format
delete data["refresh_expires_in"];
delete data["not-before-policy"];
}Additional Configuration OptionsIf you're still experiencing issues with specific fields in the response, you can use the
You can also configure additional authentication checks using TroubleshootingThe documentation notes that Langfuse authentication relies on email addresses, and when using SSO, you must ensure that the user's email address is included in their IDP profile(1). If authentication with your provider fails, try different applicable combinations of the Based on your description, setting 📚 Sources: Have another question? Just tag @inkeep. |
|
Setting The issue is that if we enable If we disable That means if the auth endpoint returns an |
Uh oh!
There was an error while loading. Please reload this page.
Describe your question
Hi, I am trying to setup SSO for self-hosted Langfuse (docker compose) to an OIDC keycloak endpoint.
When I set
AUTH_KEYCLOAK_ID_TOKEN=true: I am gettingNo email found in the user profileAccording to this issue: #4310 (comment) nextauth/langfuse is trying to get the email directly from the auth callbak object (which contains the
access_token) instead of calling theuserinfoendpoint, and to make nextauth check for theuserinfoendpoint we should disableID_TOKENThen when I set
AUTH_KEYCLOAK_ID_TOKEN=falseI am getting:Which seems to indicate now nextauth complains that there is an ID token in the response so it can't do its job (which is weird because it could still just do its job with the ACCESS_TOKEN, it does not need to fail early like this), but we need to set
ID_TOKEN=falseto fix the issue with nextauth not calling theuserinfoendpoint...I have also manually implemented the auth flow, so I can tell you that our OIDC endpoint returns this object to the callback:
{ "access_token": "###", "expires_in": 3600, "refresh_expires_in": 0, "token_type": "Bearer", "id_token": "###", "not-before-policy": 0, "session_state": "###-###-###-###-###", "scope": "openid profile email" }Note that when calling the
userinfoendpoint I properly get an email returned as part of the user object.Is there a solution to this issue? Thanks a lot
Langfuse Cloud or Self-Hosted?
Self-Hosted
If Self-Hosted
latest (3)
If Langfuse Cloud
No response
SDK and integration versions
No response
Pre-Submission Checklist
All reactions