Creating an OIDC application in Yandex Identity Hub for integration with Open WebUI
Open WebUI
For your organization's users to be able to authenticate to Open WebUI via OpenID Connect SSO, create an OIDC app in Yandex Identity Hub and configure it both in Yandex Identity Hub and Open WebUI.
OIDC apps can be managed by users with the organization-manager.oauthApplications.admin role or higher.
Note
This guide deploys Open WebUI on a Yandex Compute Cloud VM instance as an example scenario to demonstrate the integration.
To provide your organization's users with access to Open WebUI:
- Get your cloud ready.
- Create and configure an OIDC app.
- Deploy your Open WebUI instance.
- Set up integration on the Open WebUI side.
- Add a user.
- Make sure the application works correctly.
If you no longer need the resources you created, delete them.
Getting started
Sign up for Yandex Cloud and create a billing account:
- Navigate to the management console
and log in to Yandex Cloud or create a new account. - On the Yandex Cloud Billing
page, make sure you have a billing account linked and it has theACTIVEorTRIAL_ACTIVEstatus. If you do not have a billing account, create one and link a cloud to it.
If you have an active billing account, you can create or select a folder for your infrastructure on the cloud page
Learn more about clouds and folders here.
Set up your environment
-
Create a cloud network with a subnet in the same availability zone where you want to deploy your Open WebUI instance.
-
Reserve a static public IP address in the availability zone where you will deploy your Open WebUI instance.
-
In your cloud network, create a security group that allows the following traffic:
Traffic
directionPort range Protocol Source /
Destination nameIPv4 CIDR Description Inbound 80TCPAddress range0.0.0.0/0httpInbound 8080TCPAddress range0.0.0.0/08080Inbound 443TCPAddress range0.0.0.0/0httpsInbound 22TCPAddress range0.0.0.0/0sshOutbound AllAnyAddress range0.0.0.0/0any -
Create a VM from the Ubuntu 24.04 LTS public image.
Note
When creating the VM instance, select the availability zone where your subnet resides, and assign the previously reserved public IP address and security group you created.
We recommend using a VM configuration with at least 8 GB of RAM.
Required paid resources
The cost of supporting the infrastructure created in the guide includes:
- Fee for a continuously running VM (see Yandex Compute Cloud pricing).
- Fee for using a static public IP address (see Yandex Virtual Private Cloud pricing).
Create an app
- Go to Yandex Identity Hub
. - In the left-hand panel, select
Apps. - In the top-right corner, click
Create application and in the window that opens:-
Select the OIDC (OpenID Connect) single sign-on method.
-
In the Application type field, select Web Application.
OIDC apps of the
Web Applicationtype are optimized for user authentication to external web apps with a server end (backend), where the application secret can be safely stored. For more information about OIDC application types, see Types of OIDC apps in Yandex Identity Hub. -
In the Name field, specify a name for your new app:
open-webui-oidc-app. -
In the Folder field, select the folder where you want to create an OAuth client for your app.
-
Optionally, in the Description field, enter a description for the new app.
-
Optionally, add labels:
- Click Add label.
- Add a label in
key: valueformat. - Press Enter.
-
Click Create application.
-
Get the application’s credentials
-
Log in to Yandex Identity Hub
. -
In the left-hand panel, select
Apps and select the OIDC app. -
On the Overview tab, under Identity provider (IdP) configuration, copy the parameter values you need to specify in Open WebUI:
ClientID: Unique application ID.OpenID Configuration: URL with the configuration of all parameters required to set up the integration.
-
Create an app secret (only available for applications of the
Web Applicationtype).To do this, under App secrets, click Add secret, and in the window that opens:
-
Optionally, add a description for the new secret.
-
Click Create.
The window will display the generated application secret. Save this value.
Warning
If you refresh or close the application information page, you will not be able to view the secret again.
If you closed or refreshed the page before saving the secret, click Add secret to create a new one.
To delete a secret, in the list of secrets on the OIDC app page, click
in the secret row and select Delete. -
Configure the redirect URI
- Log in to Yandex Identity Hub
. - In the left-hand panel, navigate to
Apps and selectopen-webui-oidc-app. - At the top right, click
Edit and in the window that opens:-
In the Redirect URI field, specify the authentication endpoint for your Open WebUI instance:
https://<server_address>/oauth/oidc/callbackWhere
<server_address>is your previously reserved static public IP address.Note
If there is a domain name reserved for the Open WebUI instance, use this domain name as the server address.
-
Under OAuth/OIDC security, disable the Require PKCE option so that Yandex Identity Hub does not require the external application to use the PKCE security extension when exchanging data.
PKCE is a security extension used in OAuth 2.0 to minimize the risk of authentication data interception. For more information, see PKCE.
-
Click Save.
-
Deploy your Open WebUI instance
In this tutorial, you will deploy your Open WebUI instance on a Compute Cloud VM instance using a Docker
To deploy Open WebUI:
-
Connect to the VM instance you created earlier. Depending on your VM settings, you can connect to it via SSH or OS Login.
-
Install and configure Docker:
sudo apt update && sudo apt install docker.io docker-compose -
Add the current local user to the
dockergroup and start a new shell process with the updated user group membership:sudo usermod -aG docker $USER newgrp docker -
Create a directory for your Open WebUI project:
mkdir -p ~/projects/open-webui/certs cd ~/projects/open-webui/certs -
Create a self-signed TLS certificate for your Open WebUI instance:
Note
A TLS certificate is required to enable
httpsaccess to Open WebUI. When configuring OIDC app settings in Yandex Identity Hub, you must use thehttps://schema in theRedirect URI.-
Generate a private key:
openssl genrsa -out server.key 2048 -
Create a self-signed certificate valid for one year:
openssl req \ -new \ -x509 \ -key server.key \ -out server.crt \ -days 365Fill out the form that appears. In the
Common Name (e.g. server FQDN or YOUR name)field, specify the previously reserved static public IP address you assigned to the VM instance.
-
-
For convenience, rename the files you got:
mv server.crt nginx-cert.crt mv server.key nginx-cert.key -
Go to the Open WebUI project directory and create its configuration files:
cd ~/projects/open-webui touch nginx.conf touch docker-compose.yml -
Configure the Docker container environment for the initial launch of Open WebUI:
Note
You must perform the initial launch with SSO authentication disabled. This is required to create the project administrator account.
-
In a text editor, open the
docker-compose.ymlfile:nano docker-compose.yml -
Add the following configuration to the
docker-compose.ymlfile:version: '3.8' services: open-webui: image: ghcr.io/open-webui/open-webui:main container_name: open-webui environment: - WEBUI_BASE_URL=http://<VM_IP_address> ports: - "8080:8080" volumes: - open-webui-data:/app/backend/data restart: unless-stopped volumes: open-webui-data:Where
WEBUI_BASE_URLis the static public IP address of your VM instance with thehttp://schema.
-
-
In the
~/projects/open-webuidirectory, run this command:docker-compose up -dWait for all components and dependencies to download, unpack, and for the container to start:
Creating network "open-webui_default" with the default driver Creating volume "open-webui_open-webui-data" with default driver Pulling open-webui (ghcr.io/open-webui/open-webui:main)... main: Pulling from open-webui/open-webui 4f4f********: Pull complete a8ac********: Pull complete ... Digest: sha256:5c0d8f6d58ea276204b927205e43850689799f25420a67079cb988df******** Status: Downloaded newer image for ghcr.io/open-webui/open-webui:main Creating open-webui ... done -
Make sure the container is running:
docker psIf everything is configured correctly, the command output should show the
open-webuicontainer with theUp (healthy)status.Note
Depending on your VM instance configuration, starting the container may take a few minutes.
-
Create an Open WebUI administrator account:
-
In your browser, open the address of your Open WebUI instance:
http://<VM_IP_address>:8080 -
On the Open WebUI page that opens, click Get started →.
-
In the form that appears, enter the administrator’s full name, email address (login), and password.
-
Click Create Admin Account.
-
Close the browser window.
-
-
In the VM terminal, stop the Open WebUI container:
docker-compose down -
Set up your nginx
configuration that will run inside the container:-
In a text editor, open the
nginx.confconfiguration file:nano nginx.conf -
Add the following configuration to the
nginx.conffile:server { listen 80; server_name <server_address>; return 301 https://$host$request_uri; } server { listen 443 ssl; server_name <server_address>; ssl_certificate /etc/nginx/ssl/cert.crt; ssl_certificate_key /etc/nginx/ssl/key.key; location / { proxy_pass http://open-webui:8080; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for; proxy_set_header X-Forwarded-Proto $scheme; proxy_set_header X-Forwarded-Port $server_port; proxy_http_version 1.1; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection "upgrade"; proxy_buffering off; } }Where
server_name(in both sections) is the static public IP address of your VM instance. If there is a domain name reserved for the Open WebUI instance, use this domain name as the server address.
-
-
Update the Docker container configuration:
-
In a text editor, open the
docker-compose.ymlfile:nano docker-compose.yml -
Replace the
docker-compose.ymlcontents with the following configuration, specifying your Yandex Identity Hub OIDC application settings:version: '3.8' services: open-webui: image: ghcr.io/open-webui/open-webui:main container_name: open-webui environment: - WEBUI_BASE_URL=https://<server_address> - ENABLE_OAUTH_SIGNUP=true - ENABLE_LOGIN_FORM=true - ENABLE_PERSISTENT_CONFIG=true - ENABLE_OAUTH_PERSISTENT_CONFIG=true - OPENID_REDIRECT_URI=https://<server_address>/oauth/oidc/callback - OAUTH_CLIENT_ID=<client_ID_value> - OAUTH_CLIENT_SECRET=<client_secret_value> - OPENID_PROVIDER_URL=<OpenID_Configuration_value> - OAUTH_PROVIDER_NAME=Yandex Identity Hub - OAUTH_SCOPES=openid email profile ports: - "8080:8080" volumes: - open-webui-data:/app/backend/data networks: - webui-net restart: unless-stopped nginx: image: nginx:alpine container_name: nginx-webui volumes: - ./certs/nginx-cert.crt:/etc/nginx/ssl/cert.crt:ro - ./certs/nginx-cert.key:/etc/nginx/ssl/key.key:ro - ./nginx.conf:/etc/nginx/conf.d/default.conf:ro ports: - "443:443" - "80:80" depends_on: - open-webui networks: - webui-net restart: unless-stopped volumes: open-webui-data: networks: webui-net: driver: bridgeWhere:
-
WEBUI_BASE_URL: Static public IP address of your VM instance with thehttps://schema.If there is a domain name reserved for the Open WebUI instance, use this domain name as the server address.
-
OPENID_REDIRECT_URI:Redirect URIfor your Open WebUI instance. It also includes the static public IP address of your VM instance or the domain name, if one is reserved for the Open WebUI instance. -
OAUTH_CLIENT_ID:ClientIDof your Yandex Identity Hub OIDC application. -
OAUTH_CLIENT_SECRET: Yandex Identity Hub OIDC app secret. -
OPENID_PROVIDER_URL:OpenID Configurationof your Yandex Identity Hub OIDC application.
-
-
-
In the
~/projects/open-webuidirectory, restart the configuration:docker-compose up -dWait for all components and dependencies to download, unpack, and for the containers to start.
-
Make sure the containers are running:
docker psIf everything is configured correctly, the command output should show both the
nginxandopen-webuicontainers with anUporHealthystatus.Note
Depending on your VM instance configuration, starting the containers may take a few minutes.
Set up the integration on the Open WebUI side .
Complete the Open WebUI setup in the user interface:
-
In a browser window, open the address of your Open WebUI instance:
https://<server_address> -
On the login page, enter the administrator's email address and password, then click Sign in.
-
In the bottom-left corner, click your profile icon, select Settings, and navigate to Authentication.
-
In the Default User Role field, select
user. -
Make sure the OAuth / OIDC option is enabled and the following fields contain the correct data:
- Provider Name:
Yandex Identity Hub. - Provider URL:
OpenID Configurationvalue from your Yandex Identity Hub OIDC application. - Client ID:
ClientIDvalue from your Yandex Identity Hub OIDC application. - Client Secret: Yandex Identity Hub OIDC app secret.
- Redirect URI:
Redirect URIvalue from your Open WebUI instance.
If needed, populate these fields with the values you previously specified for the environment variables in
docker-compose.yml. - Provider Name:
-
Configure the additional fields as follows:
- Scopes:
openid email profile. - Email Claim:
email. - Username Claim:
preferred_username. - Sub Claim:
sub.
- Scopes:
-
Enable the OAuth Signup and Merge Accounts by Email options.
-
Leave all other settings unchanged and click Save.
Add a user
For your organization's users to be able to authenticate in Open WebUI with Yandex Identity Hub's OIDC app, you need to explicitly add these users and/or user groups to the OIDC application.
Note
Users and groups added to an OIDC application can be managed by any user with the organization-manager.oidcApplications.userAdmin role or higher.
Add a user to the application:
- Log in to Yandex Identity Hub
. - In the left-hand panel, select
Apps and select the required app. - Navigate to the Users and groups tab.
- Click
Add users. - In the window that opens, select the required user or user group.
- Click Add.
Tip
If you want to fine-tune user authentication in your applications, including authentication only from specific IP addresses, use authentication policies.
Authentication policies are a Yandex Identity Hub tool that allows you to flexibly configure access to applications by denying or allowing authentication for specific users in specific applications and/or from specific IP addresses. For more information, see Authentication policies in Yandex Identity Hub.
Make sure your application works correctly
To make sure both your OIDC app and Open WebUI integration work correctly, authenticate to Open WebUI as one of the users you added to the app.
Follow these steps:
-
In your browser, navigate to your Open WebUI instance address:
https://<server_address> -
If you were logged in to Open WebUI, log out.
-
On the Open WebUI login page, click Continue with Yandex Identity Hub.
-
On the Yandex Cloud authentication page, enter the Yandex Identity Hub user's email and password. The user or group they belong to must be added to the application.
-
Make sure you have successfully authenticated in Open WebUI.
How to delete the resources you created
To stop paying for the resources you created:
-
Delete the VM.
-
Delete the static public IP address.
-
If required, delete your other Virtual Private Cloud resources:
An availability zone is an infrastructure within a data center that hosts Yandex Cloud. For more information, see Availability zones.