Yandex Cloud
Search
Discuss with expertTry it for free
  • Customer Stories
  • Documentation
  • Blog
  • All Services
    • Cloud Interconnect
    • Cloud Backup
    • Cloud Registry
    • Yandex AI Studio
    • Compute Cloud
    • Object Storage
    • Managed Service for Kubernetes®
    • Yandex BareMetal
    • Smart Web Security
    • Security Deck
    • Managed Service for PostgreSQL
    • Managed Service for ClickHouse®
    • Monium
    • Cloud CDN
    • Network Load Balancer
    • Virtual Private Cloud
    • Cloud DNS
    • Application Load Balancer
    • Yandex Cloud Video
    • Stackland
    • Yandex Cloud Router
    • Yandex Managed Service for Trino
    • Managed Service for MySQL®
    • Managed Service for Valkey™
    • Managed Service for Apache Spark™
    • Yandex StoreDoc
    • Managed Service for OpenSearch
    • Managed Service for Apache Kafka®
    • Data Transfer
    • Yandex MPP Analytics Engine for PostgreSQL
    • Yandex Managed Service for Apache Airflow®
    • Data Processing
    • Yandex MetaData Hub
    • Managed Service for YDB
    • Managed Service for Sharded PostgreSQL
    • Managed Service for YTsaurus
    • Yandex WebSQL
    • DataLens
    • Yandex Search API
    • SpeechSense
    • SpeechKit
    • DataSphere
    • Vision OCR
    • Translate
    • Yandex Identity Hub
    • Key Management Service
    • Certificate Manager
    • Yandex Lockbox
    • Audit Trails
    • SmartCaptcha
    • Cloud Desktop
    • Yandex SIEM
    • SourceCraft Code Assistant
    • Container Registry
    • Managed Service for GitLab
    • Managed Service for Prometheus®
    • Cloud Functions
    • API Gateway
    • Yandex Cloud Postbox
    • Message Queue
    • Serverless Integrations
    • IoT Core
    • Data Streams
    • Serverless Containers
    • Cloud Notification Service
    • Yandex Query
    • Identity and Access Management
    • Yandex Cloud Console
    • Resource Manager
    • Yandex Cloud Billing
    • Yandex Cloud Quota Manager
    • Cloud Apps
  • System Status
  • Marketplace
    • Featured
    • Infrastructure & Network
    • Data Platform
    • AI for business
    • Security
    • DevOps tools
    • Serverless
    • Monitoring & Resources
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
    • Price calculator
    • Pricing plans
  • Customer Stories
  • Documentation
  • Blog
© 2026 Direct Cursus Technology L.L.C.
Tutorials
    • All tutorials
    • Differentiation of access permissions for user groups
    • Inviting a new user and assigning roles
    • Creating an L7 load balancer with a Smart Web Security profile through an Application Load Balancer ingress controller
    • Creating a distributed infrastructure with secure access
    • Centralized online publication and DDoS protection of applications
    • Basic SWS setup
    • Emergency L7 DDoS protection in Application Load Balancer
    • Delivering logs from a VM instance to Cloud Logging
    • Writing load balancer logs to PostgreSQL
    • Secure storage of GitLab CI passwords as Yandex Lockbox secrets
    • Service account with an OS Login profile for VM management via Ansible
    • Transferring logs from Container Optimized Image to Cloud Logging
    • Adding an HTML page for SmartCaptcha
    • Configuring alerts and dashboards in Monitoring
    • Uploading audit logs to Splunk SIEM
    • Uploading audit logs to ArcSight SIEM
    • Server-side encryption for an Object Storage bucket
    • Encrypting secrets in Hashicorp Terraform
    • Managing KMS keys with Hashicorp Terraform
    • Auto Unseal in Hashicorp Vault
      • 1C:Enterprise
      • Grafana OSS
      • Harbor
      • Managed Service for GitLab
      • Managed Service for OpenSearch
      • MWS
      • NetBird
      • OpenSearch
      • Open WebUI
      • Selectel
      • Sentry
      • SonarQube
      • VK Cloud
      • Zabbix
      • Passwork
      • Yandex 360
      • Yandex Browser for organizations
      • Using OAuth2 Proxy for applications not supporting SSO
    • Transferring a Yandex MPP Analytics for PostgreSQL cluster's logs to Yandex Cloud Logging
    • Obtaining the information you need to request the Russian Ministry of Digital Development to whitelist a resource
    • Uploading objects into an Object Storage bucket using an ephemeral access key

In this article:

  • Getting started
  • Set up your environment
  • Required paid resources
  • Create an app
  • Get the application’s credentials
  • Configure the redirect URI
  • Deploy your Open WebUI instance
  • Set up the integration on the Open WebUI side .
  • Add a user
  • Make sure your application works correctly
  • How to delete the resources you created
  1. Security
  2. Setting up single sign-on (SSO) for apps
  3. Open WebUI

Creating an OIDC application in Yandex Identity Hub for integration with Open WebUI

Written by
Yandex Cloud
Updated at September 25, 2026
View in Markdown
  • Getting started
    • Set up your environment
    • Required paid resources
  • Create an app
    • Get the application’s credentials
    • Configure the redirect URI
  • Deploy your Open WebUI instance
  • Set up the integration on the Open WebUI side .
  • Add a user
  • Make sure your application works correctly
  • How to delete the resources you created

Open WebUI is a free open-source platform that provides an easy way to work with large language models and can be deployed in your own infrastructure. Open WebUI supports OpenID Connect (OIDC) authentication to provide secure SSO for your organization's users.

For your organization's users to be able to authenticate to Open WebUI via OpenID Connect SSO, create an OIDC app in Yandex Identity Hub and configure it both in Yandex Identity Hub and Open WebUI.

OIDC apps can be managed by users with the organization-manager.oauthApplications.admin role or higher.

Note

This guide deploys Open WebUI on a Yandex Compute Cloud VM instance as an example scenario to demonstrate the integration.

To provide your organization's users with access to Open WebUI:

  1. Get your cloud ready.
  2. Create and configure an OIDC app.
  3. Deploy your Open WebUI instance.
  4. Set up integration on the Open WebUI side.
  5. Add a user.
  6. Make sure the application works correctly.

If you no longer need the resources you created, delete them.

Getting startedGetting started

Sign up for Yandex Cloud and create a billing account:

  1. Navigate to the management console and log in to Yandex Cloud or create a new account.
  2. On the Yandex Cloud Billing page, make sure you have a billing account linked and it has the ACTIVE or TRIAL_ACTIVE status. If you do not have a billing account, create one and link a cloud to it.

If you have an active billing account, you can create or select a folder for your infrastructure on the cloud page.

Learn more about clouds and folders here.

Set up your environmentSet up your environment

  1. Create a cloud network with a subnet in the same availability zone where you want to deploy your Open WebUI instance.

  2. Reserve a static public IP address in the availability zone where you will deploy your Open WebUI instance.

  3. In your cloud network, create a security group that allows the following traffic:

    Traffic
    direction
    Port range Protocol Source /
    Destination name
    IPv4 CIDR Description
    Inbound 80 TCP Address range 0.0.0.0/0 http
    Inbound 8080 TCP Address range 0.0.0.0/0 8080
    Inbound 443 TCP Address range 0.0.0.0/0 https
    Inbound 22 TCP Address range 0.0.0.0/0 ssh
    Outbound All Any Address range 0.0.0.0/0 any
  4. Create a VM from the Ubuntu 24.04 LTS public image.

    Note

    When creating the VM instance, select the availability zone where your subnet resides, and assign the previously reserved public IP address and security group you created.

    We recommend using a VM configuration with at least 8 GB of RAM.

Required paid resourcesRequired paid resources

The cost of supporting the infrastructure created in the guide includes:

  • Fee for a continuously running VM (see Yandex Compute Cloud pricing).
  • Fee for using a static public IP address (see Yandex Virtual Private Cloud pricing).

Create an appCreate an app

Cloud Center UI
  1. Go to Yandex Identity Hub.
  2. In the left-hand panel, select  Apps.
  3. In the top-right corner, click Create application and in the window that opens:
    1. Select the OIDC (OpenID Connect) single sign-on method.

    2. In the Application type field, select Web Application.

      OIDC apps of the Web Application type are optimized for user authentication to external web apps with a server end (backend), where the application secret can be safely stored. For more information about OIDC application types, see Types of OIDC apps in Yandex Identity Hub.

    3. In the Name field, specify a name for your new app: open-webui-oidc-app.

    4. In the Folder field, select the folder where you want to create an OAuth client for your app.

    5. Optionally, in the Description field, enter a description for the new app.

    6. Optionally, add labels:

      1. Click Add label.
      2. Add a label in key: value format.
      3. Press Enter.
    7. Click Create application.

Get the application’s credentialsGet the application’s credentials

Cloud Center UI
  1. Log in to Yandex Identity Hub.

  2. In the left-hand panel, select Apps and select the OIDC app.

  3. On the Overview tab, under Identity provider (IdP) configuration, copy the parameter values you need to specify in Open WebUI:

    • ClientID: Unique application ID.
    • OpenID Configuration: URL with the configuration of all parameters required to set up the integration.
  4. Create an app secret (only available for applications of the Web Application type).

    To do this, under App secrets, click Add secret, and in the window that opens:

    1. Optionally, add a description for the new secret.

    2. Click Create.

      The window will display the generated application secret. Save this value.

      Warning

      If you refresh or close the application information page, you will not be able to view the secret again.

    If you closed or refreshed the page before saving the secret, click Add secret to create a new one.

    To delete a secret, in the list of secrets on the OIDC app page, click in the secret row and select Delete.

Configure the redirect URIConfigure the redirect URI

Cloud Center UI
  1. Log in to Yandex Identity Hub.
  2. In the left-hand panel, navigate to Apps and select open-webui-oidc-app.
  3. At the top right, click Edit and in the window that opens:
    1. In the Redirect URI field, specify the authentication endpoint for your Open WebUI instance:

      https://<server_address>/oauth/oidc/callback
      

      Where <server_address> is your previously reserved static public IP address.

      Note

      If there is a domain name reserved for the Open WebUI instance, use this domain name as the server address.

    2. Under OAuth/OIDC security, disable the Require PKCE option so that Yandex Identity Hub does not require the external application to use the PKCE security extension when exchanging data.

      PKCE is a security extension used in OAuth 2.0 to minimize the risk of authentication data interception. For more information, see PKCE.

    3. Click Save.

Deploy your Open WebUI instanceDeploy your Open WebUI instance

In this tutorial, you will deploy your Open WebUI instance on a Compute Cloud VM instance using a Docker container.

To deploy Open WebUI:

  1. Connect to the VM instance you created earlier. Depending on your VM settings, you can connect to it via SSH or OS Login.

  2. Install and configure Docker:

    sudo apt update && sudo apt install docker.io docker-compose
    
  3. Add the current local user to the docker group and start a new shell process with the updated user group membership:

    sudo usermod -aG docker $USER
    newgrp docker
    
  4. Create a directory for your Open WebUI project:

    mkdir -p ~/projects/open-webui/certs
    cd ~/projects/open-webui/certs
    
  5. Create a self-signed TLS certificate for your Open WebUI instance:

    Note

    A TLS certificate is required to enable https access to Open WebUI. When configuring OIDC app settings in Yandex Identity Hub, you must use the https:// schema in the Redirect URI.

    1. Generate a private key:

      openssl genrsa -out server.key 2048
      
    2. Create a self-signed certificate valid for one year:

      openssl req \
        -new \
        -x509 \
        -key server.key \
        -out server.crt \
        -days 365
      

      Fill out the form that appears. In the Common Name (e.g. server FQDN or YOUR name) field, specify the previously reserved static public IP address you assigned to the VM instance.

  6. For convenience, rename the files you got:

    mv server.crt nginx-cert.crt
    mv server.key nginx-cert.key
    
  7. Go to the Open WebUI project directory and create its configuration files:

    cd ~/projects/open-webui
    touch nginx.conf
    touch docker-compose.yml
    
  8. Configure the Docker container environment for the initial launch of Open WebUI:

    Note

    You must perform the initial launch with SSO authentication disabled. This is required to create the project administrator account.

    1. In a text editor, open the docker-compose.yml file:

      nano docker-compose.yml
      
    2. Add the following configuration to the docker-compose.yml file:

      version: '3.8'
      
      services:
        open-webui:
          image: ghcr.io/open-webui/open-webui:main
          container_name: open-webui
          environment:
            - WEBUI_BASE_URL=http://<VM_IP_address>
          ports:
            - "8080:8080"
          volumes:
            - open-webui-data:/app/backend/data
          restart: unless-stopped
      
      volumes:
        open-webui-data:
      

      Where WEBUI_BASE_URL is the static public IP address of your VM instance with the http:// schema.

  9. In the ~/projects/open-webui directory, run this command:

    docker-compose up -d
    

    Wait for all components and dependencies to download, unpack, and for the container to start:

    Creating network "open-webui_default" with the default driver
    Creating volume "open-webui_open-webui-data" with default driver
    Pulling open-webui (ghcr.io/open-webui/open-webui:main)...
    main: Pulling from open-webui/open-webui
    4f4f********: Pull complete
    a8ac********: Pull complete
    ...
    Digest: sha256:5c0d8f6d58ea276204b927205e43850689799f25420a67079cb988df********
    Status: Downloaded newer image for ghcr.io/open-webui/open-webui:main
    Creating open-webui ... done
    
  10. Make sure the container is running:

    docker ps
    

    If everything is configured correctly, the command output should show the open-webui container with the Up (healthy) status.

    Note

    Depending on your VM instance configuration, starting the container may take a few minutes.

  11. Create an Open WebUI administrator account:

    1. In your browser, open the address of your Open WebUI instance:

      http://<VM_IP_address>:8080
      
    2. On the Open WebUI page that opens, click Get started →.

    3. In the form that appears, enter the administrator’s full name, email address (login), and password.

    4. Click Create Admin Account.

    5. Close the browser window.

  12. In the VM terminal, stop the Open WebUI container:

    docker-compose down
    
  13. Set up your nginx configuration that will run inside the container:

    1. In a text editor, open the nginx.conf configuration file:

      nano nginx.conf
      
    2. Add the following configuration to the nginx.conf file:

      server {
          listen 80;
          server_name <server_address>;
          return 301 https://$host$request_uri;
      }
      
      server {
          listen 443 ssl;
          server_name <server_address>;
      
          ssl_certificate     /etc/nginx/ssl/cert.crt;
          ssl_certificate_key /etc/nginx/ssl/key.key;
      
          location / {
              proxy_pass http://open-webui:8080;
              proxy_set_header Host $host;
              proxy_set_header X-Real-IP $remote_addr;
              proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
              proxy_set_header X-Forwarded-Proto $scheme;
              proxy_set_header X-Forwarded-Port $server_port;
      
              proxy_http_version 1.1;
              proxy_set_header Upgrade $http_upgrade;
              proxy_set_header Connection "upgrade";
              proxy_buffering off;
          }
      }
      

      Where server_name (in both sections) is the static public IP address of your VM instance. If there is a domain name reserved for the Open WebUI instance, use this domain name as the server address.

  14. Update the Docker container configuration:

    1. In a text editor, open the docker-compose.yml file:

      nano docker-compose.yml
      
    2. Replace the docker-compose.yml contents with the following configuration, specifying your Yandex Identity Hub OIDC application settings:

      version: '3.8'
      
      services:
        open-webui:
          image: ghcr.io/open-webui/open-webui:main
          container_name: open-webui
          environment:
            - WEBUI_BASE_URL=https://<server_address>
            - ENABLE_OAUTH_SIGNUP=true
            - ENABLE_LOGIN_FORM=true
            - ENABLE_PERSISTENT_CONFIG=true
            - ENABLE_OAUTH_PERSISTENT_CONFIG=true
            - OPENID_REDIRECT_URI=https://<server_address>/oauth/oidc/callback
            - OAUTH_CLIENT_ID=<client_ID_value>
            - OAUTH_CLIENT_SECRET=<client_secret_value>
            - OPENID_PROVIDER_URL=<OpenID_Configuration_value>
            - OAUTH_PROVIDER_NAME=Yandex Identity Hub
            - OAUTH_SCOPES=openid email profile
      
          ports:
            - "8080:8080"
          volumes:
            - open-webui-data:/app/backend/data
          networks:
            - webui-net
          restart: unless-stopped
      
        nginx:
          image: nginx:alpine
          container_name: nginx-webui
          volumes:
            - ./certs/nginx-cert.crt:/etc/nginx/ssl/cert.crt:ro
            - ./certs/nginx-cert.key:/etc/nginx/ssl/key.key:ro
            - ./nginx.conf:/etc/nginx/conf.d/default.conf:ro
          ports:
            - "443:443"
            - "80:80"
          depends_on:
            - open-webui
          networks:
            - webui-net
          restart: unless-stopped
      
      volumes:
        open-webui-data:
      
      networks:
        webui-net:
          driver: bridge
      

      Where:

      • WEBUI_BASE_URL: Static public IP address of your VM instance with the https:// schema.

        If there is a domain name reserved for the Open WebUI instance, use this domain name as the server address.

      • OPENID_REDIRECT_URI: Redirect URI for your Open WebUI instance. It also includes the static public IP address of your VM instance or the domain name, if one is reserved for the Open WebUI instance.

      • OAUTH_CLIENT_ID: ClientID of your Yandex Identity Hub OIDC application.

      • OAUTH_CLIENT_SECRET: Yandex Identity Hub OIDC app secret.

      • OPENID_PROVIDER_URL: OpenID Configuration of your Yandex Identity Hub OIDC application.

  15. In the ~/projects/open-webui directory, restart the configuration:

    docker-compose up -d
    

    Wait for all components and dependencies to download, unpack, and for the containers to start.

  16. Make sure the containers are running:

    docker ps
    

    If everything is configured correctly, the command output should show both the nginx and open-webui containers with an Up or Healthy status.

    Note

    Depending on your VM instance configuration, starting the containers may take a few minutes.

Set up the integration on the Open WebUI side .Set up the integration on the Open WebUI side .

Complete the Open WebUI setup in the user interface:

  1. In a browser window, open the address of your Open WebUI instance:

    https://<server_address>
    
  2. On the login page, enter the administrator's email address and password, then click Sign in.

  3. In the bottom-left corner, click your profile icon, select Settings, and navigate to Authentication.

  4. In the Default User Role field, select user.

  5. Make sure the OAuth / OIDC option is enabled and the following fields contain the correct data:

    • Provider Name: Yandex Identity Hub.
    • Provider URL: OpenID Configuration value from your Yandex Identity Hub OIDC application.
    • Client ID: ClientID value from your Yandex Identity Hub OIDC application.
    • Client Secret: Yandex Identity Hub OIDC app secret.
    • Redirect URI: Redirect URI value from your Open WebUI instance.

    If needed, populate these fields with the values you previously specified for the environment variables in docker-compose.yml.

  6. Configure the additional fields as follows:

    • Scopes: openid email profile.
    • Email Claim: email.
    • Username Claim: preferred_username.
    • Sub Claim: sub.
  7. Enable the OAuth Signup and Merge Accounts by Email options.

  8. Leave all other settings unchanged and click Save.

Add a userAdd a user

For your organization's users to be able to authenticate in Open WebUI with Yandex Identity Hub's OIDC app, you need to explicitly add these users and/or user groups to the OIDC application.

Note

Users and groups added to an OIDC application can be managed by any user with the organization-manager.oidcApplications.userAdmin role or higher.

Add a user to the application:

Cloud Center UI
  1. Log in to Yandex Identity Hub.
  2. In the left-hand panel, select Apps and select the required app.
  3. Navigate to the Users and groups tab.
  4. Click Add users.
  5. In the window that opens, select the required user or user group.
  6. Click Add.

Tip

If you want to fine-tune user authentication in your applications, including authentication only from specific IP addresses, use authentication policies.

Authentication policies are a Yandex Identity Hub tool that allows you to flexibly configure access to applications by denying or allowing authentication for specific users in specific applications and/or from specific IP addresses. For more information, see Authentication policies in Yandex Identity Hub.

Make sure your application works correctlyMake sure your application works correctly

To make sure both your OIDC app and Open WebUI integration work correctly, authenticate to Open WebUI as one of the users you added to the app.

Follow these steps:

  1. In your browser, navigate to your Open WebUI instance address:

    https://<server_address>
    
  2. If you were logged in to Open WebUI, log out.

  3. On the Open WebUI login page, click Continue with Yandex Identity Hub.

  4. On the Yandex Cloud authentication page, enter the Yandex Identity Hub user's email and password. The user or group they belong to must be added to the application.

  5. Make sure you have successfully authenticated in Open WebUI.

How to delete the resources you createdHow to delete the resources you created

To stop paying for the resources you created:

  1. Delete the VM.

  2. Delete the static public IP address.

  3. If required, delete your other Virtual Private Cloud resources:

    1. Security group.
    2. Subnet.
    3. Cloud network.

An availability zone is an infrastructure within a data center that hosts Yandex Cloud. For more information, see Availability zones.

Was the article helpful?

Previous
OpenVPN Community Edition
Next
Selectel
© 2026 Direct Cursus Technology L.L.C.