Yandex Cloud
Search
Discuss with expertTry it for free
  • Customer Stories
  • Documentation
  • Blog
  • All Services
    • Cloud Interconnect
    • Cloud Backup
    • Cloud Registry
    • Yandex AI Studio
    • Compute Cloud
    • Object Storage
    • Managed Service for Kubernetes®
    • Yandex BareMetal
    • Smart Web Security
    • Security Deck
    • Managed Service for PostgreSQL
    • Managed Service for ClickHouse®
    • Monium
    • Cloud CDN
    • Network Load Balancer
    • Virtual Private Cloud
    • Cloud DNS
    • Application Load Balancer
    • Yandex Cloud Video
    • Stackland
    • Yandex Cloud Router
    • Yandex Managed Service for Trino
    • Managed Service for MySQL®
    • Managed Service for Valkey™
    • Managed Service for Apache Spark™
    • Yandex StoreDoc
    • Managed Service for OpenSearch
    • Managed Service for Apache Kafka®
    • Data Transfer
    • Yandex MPP Analytics Engine for PostgreSQL
    • Yandex Managed Service for Apache Airflow®
    • Data Processing
    • Yandex MetaData Hub
    • Managed Service for YDB
    • Managed Service for Sharded PostgreSQL
    • Managed Service for YTsaurus
    • Yandex WebSQL
    • DataLens
    • Yandex Search API
    • SpeechSense
    • SpeechKit
    • DataSphere
    • Vision OCR
    • Translate
    • Yandex Identity Hub
    • Key Management Service
    • Certificate Manager
    • Yandex Lockbox
    • Audit Trails
    • SmartCaptcha
    • Cloud Desktop
    • Yandex SIEM
    • SourceCraft Code Assistant
    • Container Registry
    • Managed Service for GitLab
    • Managed Service for Prometheus®
    • Cloud Functions
    • API Gateway
    • Yandex Cloud Postbox
    • Message Queue
    • Serverless Integrations
    • IoT Core
    • Data Streams
    • Serverless Containers
    • Cloud Notification Service
    • Yandex Query
    • Identity and Access Management
    • Yandex Cloud Console
    • Resource Manager
    • Yandex Cloud Billing
    • Yandex Cloud Quota Manager
    • Cloud Apps
  • System Status
  • Marketplace
    • Featured
    • Infrastructure & Network
    • Data Platform
    • AI for business
    • Security
    • DevOps tools
    • Serverless
    • Monitoring & Resources
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
    • Price calculator
    • Pricing plans
  • Customer Stories
  • Documentation
  • Blog
© 2026 Direct Cursus Technology L.L.C.
Yandex Identity Hub
    • All tutorials
    • Differentiation of access permissions for user groups
    • Service account with an OS Login profile for VM management via Ansible
      • Overview
      • 1C:Enterprise
      • Grafana OSS
      • Harbor
        • SAML
        • OpenID Connect
      • Managed Service for GitLab
      • Managed Service for OpenSearch
      • MWS
      • NetBird
      • OpenSearch
      • Open WebUI
      • Selectel
      • Sentry
      • SonarQube
      • VK Cloud
      • Zabbix
      • Passwork
      • Yandex 360
      • Yandex Browser for organizations
      • Using OAuth2 Proxy for applications not supporting SSO
  • Access management
  • Pricing policy
  • Terraform reference
  • Audit Trails events
  • Release notes
  • Yandex Identity Hub Sync Agent release notes

In this article:

  • Create an app
  • Set up the integration
  • Get the application's credentials and create the application's secret
  • Configure advanced OIDC app settings in Yandex Identity Hub
  • Set up OIDC authentication in LibreChat
  • Add users
  • Make sure your application works correctly
  1. Tutorials
  2. Setting up single sign-on (SSO) for apps
  3. LibreChat
  4. OpenID Connect

Creating an OIDC application in Yandex Identity Hub for integration with LibreChat

Written by
Yandex Cloud
Updated at September 25, 2026
View in Markdown
  • Create an app
  • Set up the integration
    • Get the application's credentials and create the application's secret
    • Configure advanced OIDC app settings in Yandex Identity Hub
    • Set up OIDC authentication in LibreChat
  • Add users
  • Make sure your application works correctly

LibreChat is a free open-source platform that provides an easy way to work with large language models, AI agents, and MCP servers and can be deployed in your own infrastructure. LibreChat supports OpenID Connect (OIDC) authentication to provide secure SSO for your organization's users.

For your organization's users to be able to authenticate to LibreChat via OpenID Connect SSO, create an OIDC app in Yandex Identity Hub and configure it both in Yandex Identity Hub and LibreChat.

OIDC apps can be managed by users with the organization-manager.oauthApplications.admin role or higher.

To provide your organization's users with access to LibreChat:

  1. Create an app.
  2. Set up the integration.
  3. Add users.
  4. Make sure the application works correctly.

Create an appCreate an app

Cloud Center UI
  1. Log in to Yandex Identity Hub.
  2. In the left-hand panel, select  Apps.
  3. In the top-right corner, click Create application and in the window that opens:
    1. Select the OIDC (OpenID Connect) single sign-on method.
    2. In the Application type field, select Web Application.

      OIDC apps of the Web Application type are optimized for user authentication to external web apps with a server end (backend), where the application secret can be safely stored. For more information about OIDC application types, see Types of OIDC apps in Yandex Identity Hub.

    3. In the Name field, specify a name for your new app: librechat-oidc-app.
    4. In the Folder field, select the folder where you want to create an OAuth client for your app.
    5. Optionally, add a description and labels for the app.
    6. Click Create application.

Set up the integrationSet up the integration

To configure LibreChat integration with the OIDC app you created in Yandex Identity Hub, complete the configuration both on the Yandex Identity Hub side and in LibreChat.

Get the application's credentials and create the application's secretGet the application's credentials and create the application's secret

Cloud Center UI
  1. Log in to Yandex Identity Hub.
  2. In the left-hand panel, navigate to Apps and select librechat-oidc-app.
  3. On the Overview tab, under Identity provider (IdP) configuration, copy the ClientID field value.
  4. Create an app secret (only available for applications of the Web Application type).

    To do this, under App secrets, click Add secret, and in the window that opens:

    1. Optionally, add a description for the new secret.

    2. Click Create.

      The window will display the generated application secret. Save this value.

      Warning

      If you refresh or close the application information page, you will not be able to view the secret again.

    If you closed or refreshed the page before saving the secret, click Add secret to create a new one.

    To delete a secret, in the list of secrets on the OIDC app page, click in the secret row and select Delete.

Configure advanced OIDC app settings in Yandex Identity HubConfigure advanced OIDC app settings in Yandex Identity Hub

Cloud Center UI
  1. Log in to Yandex Identity Hub.

  2. In the left-hand panel, navigate to Apps and select librechat-oidc-app.

  3. At the top right, click Edit and in the window that opens:

    1. Set the Redirect URI field to https://<server_address>/oauth/openid/callback, where <server_address> is the public IP address or domain name of your LibreChat instance.

      Note

      In the Yandex Identity Hub OIDC app settings, the Redirect URI value only supports the https:// scheme, so your LibreChat instance must be accessible over https.

    2. Under Scopes, enable groups (user's groups in the organization).

    3. Click Save.

Set up OIDC authentication in LibreChatSet up OIDC authentication in LibreChat

  1. On the host running your LibreChat instance, set the following environment variables in the instance runtime environment to configure LibreChat integration with the OIDC application:

    • Variables defining the main integration settings:

      Variable name Value
      OPENID_CLIENT_ID ClientID field value obtained earlier from the Yandex Cloud OIDC app settings
      OPENID_CLIENT_SECRET OIDC app secret generated earlier
      OPENID_ISSUER "https://auth.yandex.cloud/"
      OPENID_SESSION_SECRET Additional secret used to secure sessions.

      Generate a strong secret of at least 32 characters.
      OPENID_SCOPE "openid profile email groups"
      OPENID_CALLBACK_URL "/oauth/openid/callback"
      OPENID_USERNAME_CLAIM "preferred_username"
      OPENID_NAME_CLAIM "name"
      OPENID_EMAIL_CLAIM "email"
      OPENID_USE_PKCE true
      OPENID_BUTTON_LABEL "Login with Yandex Identity Hub"
      OPENID_AUTO_REDIRECT false
    • Variables defining advanced settings for user group synchronization:

      Variable name Value
      OPENID_ROLE_SYNC_ENABLED true
      OPENID_ROLE_SYNC_API_ENABLED false
      OPENID_ROLE_SYNC_SOURCE "id"
      OPENID_ROLE_SYNC_CLAIM "groups"
      OPENID_ROLE_SYNC_ROLE_PRIORITY List of group names in Yandex Identity Hub to synchronize with.

      Here is an example: "librechat-admins,librechat-users".
      OPENID_ROLE_SYNC_FALLBACK_ROLE Default user group.

      Here is an example: "librechat-users".
  2. Restart your LibreChat instance in the runtime environment with the specified environment variables.

Add usersAdd users

To enable users to authenticate in LibreChat:

  1. In Yandex Identity Hub, create a user group under one of the names specified earlier in the OPENID_ROLE_SYNC_ROLE_PRIORITY environment variable, e.g., librechat-users.

  2. Add a user to the librechat-users group.

  3. Add the librechat-users group to the Yandex Identity Hub OIDC app:

    Note

    Users and groups added to an OIDC application can be managed by any user with the organization-manager.oidcApplications.userAdmin role or higher.

    Cloud Center UI
    1. Log in to Yandex Identity Hub.
    2. In the left-hand panel, navigate to Apps and select librechat-oidc-app.
    3. Navigate to the Users and groups tab.
    4. Click Add users.
    5. In the window that opens, navigate to the Groups tab and select librechat-users.
    6. Click Add.

Tip

If you want to fine-tune user authentication in your applications, including authentication only from specific IP addresses, use authentication policies.

Authentication policies are a Yandex Identity Hub tool that allows you to flexibly configure access to applications by denying or allowing authentication for specific users in specific applications and/or from specific IP addresses. For more information, see Authentication policies in Yandex Identity Hub.

Make sure your application works correctlyMake sure your application works correctly

To ensure that your OIDC application and integration with LibreChat are working correctly, log in to LibreChat as one of the users added to the librechat-users group. Follow these steps:

  1. In your browser, open the LibreChat instance login page.
  2. Select login via Yandex Identity Hub.
  3. Authenticate in Yandex Cloud as a user of your organization.
  4. After authenticating successfully, make sure you are logged in to LibreChat and your authorized user belongs to the same group, librechat-users, in both LibreChat and Yandex Identity Hub.

Was the article helpful?

Previous
SAML
Next
SAML
© 2026 Direct Cursus Technology L.L.C.