OpenID Connect
Use a generic OpenID Connect (OIDC) provider for sign-in to a self-hosted Coolify instance. Configure it as a root team administrator or owner under Settings > Authentication > OpenID Connect.
Configure the provider
- Create a confidential web application at your identity provider.
- Copy the Redirect URI displayed by Coolify into the provider's allowed redirect URIs. Keep an exact match, including the scheme and path.
- Enter the Issuer URL, Client ID, and Client secret in Coolify. Coolify discovers the authorization, token, userinfo, and JWKS endpoints from the issuer.
- Set Scopes to include
openid. Includeemailandprofilewhen supported. Request any additional scopes your provider requires. - Configure Use PKCE, Require verified email, and Clock skew (seconds) for your provider. You can customize the Login button label.
- Save the settings and enable the provider.
Configure the instance URL before setup so Coolify generates the correct default callback URL.
Registration and team membership
Allow OIDC user creation permits a successful OIDC login to create a user when password registration is disabled. Disable it when only existing users should sign in. Auto-join new users to Root team adds newly created users as members without creating a personal team.
Under Settings > Authentication, you can disable password registration while OAuth is enabled. Review OAuth account linking before linking existing users. Existing-account linking requires a verified email address; disabling the OIDC verification setting does not bypass that requirement.
Microsoft Entra ID
Use this issuer URL, replacing the tenant placeholder:
https://login.microsoftonline.com/<tenant-ID>/v2.0In the app registration, add the optional ID token claims email and xms_edov. Coolify accepts xms_edov as evidence of email verification. Register the OIDC callback displayed by Coolify, rather than the callback for the separate Microsoft OAuth integration.
Verify sign-in
Test in a private browser window with an approved non-root user. Confirm that the expected account and team open, new account creation follows your policy, and Coolify requests a 2FA code when enabled. Linked identities appear on Profile; provider-managed email addresses cannot be edited there.
If login fails, read the reason on the login page and check the issuer, callback, scopes, and email-verification claims. Keep an administrator recovery sign-in available while testing.
