Single sign-on (SSO)
eodia analytics accepts sign-in with a password and with OpenID Connect (Keycloak, Microsoft Entra ID, Google, Authentik… any provider that publishes a discovery configuration). A single provider is declared per instance, through environment variables. It is the same mechanism as in eodia insights: the same provider can serve both.
Declaring the provider
Section titled “Declaring the provider”With the provider, register a web application with this redirect address:
https://stats.example.com/api/auth/oidc/callbackIt is derived from PUBLIC_URL: check that this variable gives the public address of the
instance. Then, on the eodia analytics side:
OIDC_ISSUER=https://sso.example.com/realms/entrepriseOIDC_CLIENT_ID=eodia-analyticsOIDC_CLIENT_SECRET=…OIDC_LABEL="Sign in with your company account"Sign-in follows the authorization code flow with PKCE. The ID token is verified with the
keys published by the provider (issuer, audience, nonce).
Accounts
Section titled “Accounts”The first time a person signs in:
- if their OIDC identity is already linked to an account, they sign in to it;
- otherwise, if an account has the same email address, the identity is linked to it;
- otherwise, an account is created, with the address and name sent by the provider.
The provider must therefore send an email address (email). An account deactivated in
Administration › People can no longer sign in, even through SSO.
Groups
Section titled “Groups”OIDC_GROUPS_CLAIM=groupsWith this variable, the provider’s groups are mirrored at each sign-in: the person is removed from their custom groups, then added to those whose name appears in the claim. The groups must exist in eodia analytics with the same name; those that do not exist are ignored.
Access to sites is granted per group, in each site’s Settings: read access (installation, verification, statistics) or edit access (settings, metadata). Administrators see everything; creating a site is reserved for them.
SSO only
Section titled “SSO only”PASSWORD_LOGIN=0The sign-in screen then offers only the provider’s button, and the API rejects any password sign-in. On a new instance, the screen for creating the first administrator is still offered: give it the email address of their account with the provider, since they will then sign in through SSO and their account will be found by that address.
Administration › Settings shows whether SSO and email sending are configured.
eodia analytics is free software by Eodia.