Creating an OIDC application in Yandex Identity Hub for integration with LibreChat
LibreChat
For your organization's users to be able to authenticate to LibreChat via OpenID Connect SSO, create an OIDC app in Yandex Identity Hub and configure it both in Yandex Identity Hub and LibreChat.
OIDC apps can be managed by users with the organization-manager.oauthApplications.admin role or higher.
To provide your organization's users with access to LibreChat:
Create an app
- Log in to Yandex Identity Hub
. - In the left-hand panel, select
Apps. - In the top-right corner, click
Create application and in the window that opens:- Select the OIDC (OpenID Connect) single sign-on method.
-
In the Application type field, select Web Application.
OIDC apps of the
Web Applicationtype are optimized for user authentication to external web apps with a server end (backend), where the application secret can be safely stored. For more information about OIDC application types, see Types of OIDC apps in Yandex Identity Hub. - In the Name field, specify a name for your new app:
librechat-oidc-app. - In the Folder field, select the folder where you want to create an OAuth client for your app.
- Optionally, add a description and labels for the app.
- Click Create application.
Set up the integration
To configure LibreChat integration with the OIDC app you created in Yandex Identity Hub, complete the configuration both on the Yandex Identity Hub side and in LibreChat.
Get the application's credentials and create the application's secret
- Log in to Yandex Identity Hub
. - In the left-hand panel, navigate to
Apps and selectlibrechat-oidc-app. - On the Overview tab, under Identity provider (IdP) configuration, copy the ClientID field value.
-
Create an app secret (only available for applications of the
Web Applicationtype).To do this, under App secrets, click Add secret, and in the window that opens:
-
Optionally, add a description for the new secret.
-
Click Create.
The window will display the generated application secret. Save this value.
Warning
If you refresh or close the application information page, you will not be able to view the secret again.
If you closed or refreshed the page before saving the secret, click Add secret to create a new one.
To delete a secret, in the list of secrets on the OIDC app page, click
in the secret row and select Delete. -
Configure advanced OIDC app settings in Yandex Identity Hub
-
Log in to Yandex Identity Hub
. -
In the left-hand panel, navigate to
Apps and selectlibrechat-oidc-app. -
At the top right, click
Edit and in the window that opens:-
Set the Redirect URI field to
https://<server_address>/oauth/openid/callback, where<server_address>is the public IP address or domain name of your LibreChat instance.Note
In the Yandex Identity Hub OIDC app settings, the
Redirect URIvalue only supports thehttps://scheme, so your LibreChat instance must be accessible overhttps. -
Under Scopes, enable groups (user's groups in the organization).
-
Click Save.
-
Set up OIDC authentication in LibreChat
-
On the host running your LibreChat instance, set the following environment variables in the instance runtime environment to configure LibreChat integration with the OIDC application:
-
Variables defining the main integration settings:
Variable name Value OPENID_CLIENT_IDClientID field value obtained earlier from the Yandex Cloud OIDC app settings OPENID_CLIENT_SECRETOIDC app secret generated earlier OPENID_ISSUER"https://auth.yandex.cloud/"OPENID_SESSION_SECRETAdditional secret used to secure sessions.Generate a strong secret of at least 32 characters. OPENID_SCOPE"openid profile email groups"OPENID_CALLBACK_URL"/oauth/openid/callback"OPENID_USERNAME_CLAIM"preferred_username"OPENID_NAME_CLAIM"name"OPENID_EMAIL_CLAIM"email"OPENID_USE_PKCEtrueOPENID_BUTTON_LABEL"Login with Yandex Identity Hub"OPENID_AUTO_REDIRECTfalse -
Variables defining advanced settings for user group synchronization:
Variable name Value OPENID_ROLE_SYNC_ENABLEDtrueOPENID_ROLE_SYNC_API_ENABLEDfalseOPENID_ROLE_SYNC_SOURCE"id"OPENID_ROLE_SYNC_CLAIM"groups"OPENID_ROLE_SYNC_ROLE_PRIORITYList of group names in Yandex Identity Hub to synchronize with.Here is an example: "librechat-admins,librechat-users".OPENID_ROLE_SYNC_FALLBACK_ROLEDefault user group.Here is an example: "librechat-users".
-
-
Restart your LibreChat instance in the runtime environment with the specified environment variables.
Add users
To enable users to authenticate in LibreChat:
-
In Yandex Identity Hub, create a user group under one of the names specified earlier in the
OPENID_ROLE_SYNC_ROLE_PRIORITYenvironment variable, e.g.,librechat-users. -
Add a user to the
librechat-usersgroup. -
Add the
librechat-usersgroup to the Yandex Identity Hub OIDC app:Note
Users and groups added to an OIDC application can be managed by any user with the
organization-manager.oidcApplications.userAdminrole or higher.Cloud Center UI- Log in to Yandex Identity Hub
. - In the left-hand panel, navigate to
Apps and selectlibrechat-oidc-app. - Navigate to the Users and groups tab.
- Click
Add users. - In the window that opens, navigate to the Groups tab and select
librechat-users. - Click Add.
- Log in to Yandex Identity Hub
Tip
If you want to fine-tune user authentication in your applications, including authentication only from specific IP addresses, use authentication policies.
Authentication policies are a Yandex Identity Hub tool that allows you to flexibly configure access to applications by denying or allowing authentication for specific users in specific applications and/or from specific IP addresses. For more information, see Authentication policies in Yandex Identity Hub.
Make sure your application works correctly
To ensure that your OIDC application and integration with LibreChat are working correctly, log in to LibreChat as one of the users added to the librechat-users group. Follow these steps:
- In your browser, open the LibreChat instance login page.
- Select login via Yandex Identity Hub.
- Authenticate in Yandex Cloud as a user of your organization.
- After authenticating successfully, make sure you are logged in to LibreChat and your authorized user belongs to the same group,
librechat-users, in both LibreChat and Yandex Identity Hub.