-
Notifications
You must be signed in to change notification settings - Fork 70
Howto GitHub OIDC
GitHub does not expose a native OIDC discovery endpoint, so Bindery uses Dex as a standards-compliant OIDC bridge. This guide wires GitHub → Dex → Bindery.
What you'll have at the end: a "Sign in with GitHub" button on the Bindery login page. Dex handles the GitHub OAuth dance; Bindery sees a standard OIDC token with a stable numeric sub (GitHub user ID — survives username changes).
Prerequisites:
- Dex v2.37+ running and reachable from Bindery and from users' browsers
- Bindery v0.24.0+
- A GitHub account to register an OAuth App
- Go to GitHub → Settings → Developer settings → OAuth Apps → New OAuth App.
- Fill in:
- Application name: Bindery
-
Homepage URL:
https://bindery.example.com -
Authorization callback URL:
https://dex.example.com/callback
- Click Register application. Copy the Client ID.
- Click Generate a new client secret. Copy the secret immediately — it's shown once.
Expected result: App appears in your OAuth Apps list with a Client ID like Iv1.abc123.
# dex/config.yaml
issuer: https://dex.example.com
storage:
type: sqlite3
config:
file: /var/dex/dex.db
web:
http: 0.0.0.0:5556
connectors:
- type: github
id: github
name: GitHub
config:
clientID: <github-oauth-app-client-id>
clientSecret: <github-oauth-app-client-secret>
redirectURI: https://dex.example.com/callback
# Optional: restrict to org members
orgs:
- name: your-github-org
staticClients:
- id: bindery
secret: <dex-client-secret> # generate: openssl rand -hex 32
name: Bindery
redirectURIs:
- https://bindery.example.com/api/v1/auth/oidc/github/callbackRestart Dex after saving. Confirm it's healthy:
curl -s https://dex.example.com/.well-known/openid-configuration | jq .issuer
# Expected: "https://dex.example.com"environment:
BINDERY_OIDC_REDIRECT_BASE_URL: "https://bindery.example.com"Restart Bindery if adding for the first time.
Settings → Security → OIDC Providers → Add provider, or:
curl -X POST http://bindery:8787/api/v1/settings/auth/oidc/providers \
-H "X-Api-Key: <admin-key>" \
-H "Content-Type: application/json" \
-d '{
"id": "github",
"name": "GitHub",
"issuer": "https://dex.example.com",
"client_id": "bindery",
"client_secret": "<dex-client-secret>",
"scopes": "openid email profile"
}'Note: client_id and client_secret here are the Dex static client credentials, not the GitHub OAuth App credentials. The GitHub credentials live only in Dex's config.
Expected result: provider saved, Sign in with GitHub button appears on the login page.
- Open a private window →
https://bindery.example.com/login→ click Sign in with GitHub. - Browser goes to Dex (
dex.example.com) → Dex redirects to GitHub → you authorize → GitHub sends code to Dex → Dex exchanges it → Dex issues an ID token to Bindery. - Bindery maps the user by
(https://dex.example.com, <dex-sub>). Dex'ssubfor GitHub users is the numeric GitHub user ID — stable even if the GitHub username changes. - Bindery provisions the user account and logs you in. Check Settings → Users to confirm.
In the Dex config, the orgs block limits logins to members of the specified org. To further restrict to a specific team:
orgs:
- name: your-github-org
teams:
- bindery-usersUsers outside the org/team get a Dex error before Bindery is reached.
| Symptom | Cause | Fix |
|---|---|---|
| Dex discovery URL returns 404 | Dex not running or wrong URL |
curl https://dex.example.com/.well-known/openid-configuration — should return JSON |
redirect_uri_mismatch from GitHub |
GitHub OAuth App callback URL doesn't match Dex | Must be exactly https://dex.example.com/callback — update in GitHub OAuth App settings |
redirect_uri_mismatch from Dex |
Dex staticClients.redirectURIs doesn't match Bindery callback |
Must be https://bindery.example.com/api/v1/auth/oidc/github/callback
|
connector not found error in Dex logs |
Dex config missing or not reloaded | Restart Dex after editing config.yaml
|
| User can log in but gets a different Bindery account after a GitHub username change | Using preferred_username (mutable) as identity |
Dex uses the numeric GitHub user ID as sub — this should not happen. If it does, check whether you've overridden the claims mapping in Dex |
| Org restriction not working — non-members can log in |
orgs block missing or Dex not reloaded |
Confirm the orgs block in Dex config and restart Dex |
See also: Troubleshooting — OIDC | docs/auth-oidc.md
Getting started
Setup guides
How-to guides — proxy auth (v1.0)
How-to guides — OIDC (v1.0)
- Google Sign-In
- GitHub OAuth via Dex
- Authelia as OIDC provider
- Authentik
- Keycloak
- Rotate OIDC client secrets
- Recover from broken OIDC
How-to guides — multi-user (v1.0)
Reference
Contributing