See also
Broadly speaking, the Overleaf CE+ OIDC documentation is good, but there are a few other resources worth a read:
Authentik config
Create a new application with an OIDC provider. All settings can be left as default, with the exception of:
- Redirect URIs — add/edit one as follows:
- Strict:
https://overleaf.example.com/oidc/login/callback
- Strict:
Record the values of the client ID and secret; you will need them for the Overleaf config.
Configure user/group directory access as usual (Application ⇒ Policy / User / Group bindings) to grant permissions.
Overleaf config
Single administrator
This approach grants a single user admin rights on Overleaf. See the second link in the “see also” note above for an approach on multiple admins, though I couldn’t get it to work immediately.
Add the following environment variables (via env file, Docker compose, whatever):
# tell overleaf what URL it's calling authentik from
# this is the same value as VIRTUAL_HOST environ if you have that set
OVERLEAF_SITE_URL=https://overleaf.example.com
# enable OIDC
EXTERNAL_AUTH=oidc
# endpoint URLs
OVERLEAF_OIDC_ISSUER=https://auth.example.com/application/o/overleaf
OVERLEAF_OIDC_AUTHORIZATION_URL=https://auth.example.com/o/authorize
OVERLEAF_OIDC_TOKEN_URL=https://auth.example.com/o/token
OVERLEAF_OIDC_USER_INFO_URL=https://auth.example.com/o/userinfo
OVERLEAF_OIDC_LOGOUT_URL=https://auth.example.com/o/overleaf/end-session
# set the secrets
OVERLEAF_OIDC_CLIENT_ID=<the client ID from authentik>
OVERLEAF_OIDC_CLIENT_SECRET=<the client secret from authentik>
# configure overleaf to use authentik
OVERLEAF_OIDC_SCOPE=openid email profile
OVERLEAF_OIDC_USER_ID_FIELD=id
OVERLEAF_OIDC_ALLOWED_EMAIL_DOMAINS=example.com
OVERLEAF_OIDC_UPDATE_USER_DETAILS_ON_LOGIN=true
# pick a user to be admin
OVERLEAF_OIDC_IS_ADMIN_FIELD=email
OVERLEAF_OIDC_IS_ADMIN_FIELD_VALUE=misha@example.com
# what to display on the "Log in with XYZ" button on the webpage
OVERLEAF_OIDC_PROVIDER_NAME=Authentik
OVERLEAF_OIDC_IDENTITY_SERVICE=Authentik
See also
This should go in, near, or alongside your Overleaf container environment variable file. See Overleaf container.