# OIDC configuration - Weaviate

**URL:** <https://forum.weaviate.io/t/oidc-configuration-weaviate/2099>\
**Category:** Support\
**Created:** [April 24, 2024, 1:31am UTC](https://forum.weaviate.io/t/oidc-configuration-weaviate/2099 "2024-04-24T01:31:37Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![adithya.ch](https://yyz1.discourse-cdn.com/flex027/user_avatar/forum.weaviate.io/adithya.ch/32/615_2.png) [@adithya.ch](https://forum.weaviate.io/u/adithya.ch)\
**Post date:** [April 24, 2024, 1:31am UTC](https://forum.weaviate.io/t/oidc-configuration-weaviate/2099/1 "2024-04-24T01:31:37Z")

</div>

### Description

I am trying to enable OIDC configuration for weaviate cluster

config added:

export AUTHENTICATION\_OIDC\_ENABLED=true  
export AUTHENTICATION\_OIDC\_ISSUER=“{issuer\_url}”  
export AUTHENTICATION\_OIDC\_CLIENT\_ID=“{client\_id}”

verified the same in logs as well

time=“2024-04-23T18:01:36-07:00” level=debug msg=“configured OIDC and anonymous access client” action=startup startup\_time\_left=59m59.708999607s

```auto
http://weaviate-server:8080/v1/.well-known/openid-configuration

```

So configuration is set properly at weaviate server level.

OIDC config supports **authorization\_code**. So we are trying to access weaviate using bearer\_token  
using the document [Authentication | Weaviate Documentation](https://weaviate.io/developers/weaviate/configuration/authentication#oidc---a-systems-perspective)

in the document it’s mentioned to run below to get access\_token

```auto
* `{authorization_endpoint}`?client_id=`{clientId}`&response_type=code%20id_token&response_mode=fragment&redirect_url=`{redirect_url}`&scope=openid&nonce=abcd
* the `redirect_url` must have been [pre-registered](https://openid.net/specs/openid-connect-core-1_0.html#AuthRequest) with your token issuer.

```

I tried getting all the details and ran the request in browser

**Error:** Response type requested: “id\_token”; The Implict grant type flow is not supported. Please change the grant type on your application to one of the supported values.

If i don’t use id\_token in the url, it routes to weviate-url homepage and i see code(token) in the url

```auto
http://weaviate-server:8080/v1#code= ************ 723aa3c

```

I tried to login using this code as bearer\_token, but connection fails.

curl [http://weaviate-server:8080/v1/objects](http://weaviate-server:8080/v1/objects) -H “Authorization: Bearer \*\*\*\*\*\*\*\*\*\*\*\*723aa3c” | jq  
% Total % Received % Xferd Average Speed Time Time Time Current  
Dload Upload Total Spent Left Speed  
100 89 100 89 0 0 44500 0 --:–:-- --:–:-- --:–:-- 44500  
{  
“code”: 401,  
“message”: “oidc: malformed jwt: oidc: malformed jwt, expected 3 parts got 1”

Let me know how to fix this issue ?

Regards.  
Adithya

### Server Setup Information

- Weaviate Server Version: 1.23
- Deployment Method: On VM’s
- Multi Node? Number of Running Nodes: yes
- Client Language and Version: Python v4

---

<div class="post-metadata">

**Author:** ![adithya.ch](https://yyz1.discourse-cdn.com/flex027/user_avatar/forum.weaviate.io/adithya.ch/32/615_2.png) [@adithya.ch](https://forum.weaviate.io/u/adithya.ch)\
**Post date:** [April 24, 2024, 3:48am UTC](https://forum.weaviate.io/t/oidc-configuration-weaviate/2099/2 "2024-04-24T03:48:15Z")

</div>

Hi Team,

our OIDC support below response/grant types.

“response\_types\_supported”: [  
“code”  
],  
“scopes\_supported”: [  
“openid”,  
“offline\_access”  
],  
“response\_modes\_supported”: [  
“query”,  
“fragment”  
],  
“grant\_types\_supported”: [  
“authorization\_code”,  
“refresh\_token”  
],

Let me know how to configure the OIDC with these grant types !

Regards,  
Adithya

---

<div class="post-metadata">

**Author:** ![DudaNogueira](https://yyz1.discourse-cdn.com/flex027/user_avatar/forum.weaviate.io/dudanogueira/32/7846_2.png) [@DudaNogueira](https://forum.weaviate.io/u/DudaNogueira)\
**Post date:** [April 24, 2024, 5:47pm UTC](https://forum.weaviate.io/t/oidc-configuration-weaviate/2099/3 "2024-04-24T17:47:44Z")

</div>

Hi @adithya.ch !

I’ll take a look on this later today. I have not played with OIDC yet, and this is a great opportunity to do it 🙂

I’ll get back here with more info!

---

<div class="post-metadata">

**Author:** ![adithya.ch](https://yyz1.discourse-cdn.com/flex027/user_avatar/forum.weaviate.io/adithya.ch/32/615_2.png) [@adithya.ch](https://forum.weaviate.io/u/adithya.ch)\
**Post date:** [April 24, 2024, 7:50pm UTC](https://forum.weaviate.io/t/oidc-configuration-weaviate/2099/4 "2024-04-24T19:50:19Z")

</div>

Sure @DudaNogueira . Thank you

**api\_key** authentication mechanism is not much secured as the keys (passwords) are plain text and who ever have access to values.yaml will be able to use these keys to connect. If we want to add new users, i need to update the values.yaml and update helm chart again which will in turn restarts the pods again which we want to avoid

It would be great if we make DUO OIDC work with weaviate.

Regards,  
Adithya

---

<div class="post-metadata">

**Author:** ![adithya.ch](https://yyz1.discourse-cdn.com/flex027/user_avatar/forum.weaviate.io/adithya.ch/32/615_2.png) [@adithya.ch](https://forum.weaviate.io/u/adithya.ch)\
**Post date:** [April 26, 2024, 8:55pm UTC](https://forum.weaviate.io/t/oidc-configuration-weaviate/2099/5 "2024-04-26T20:55:21Z")

</div>

@DudaNogueira , Please let me know if any updates about this OIDC issue ?

Regards,  
Adithya

---

<div class="post-metadata">

**Author:** ![DudaNogueira](https://yyz1.discourse-cdn.com/flex027/user_avatar/forum.weaviate.io/dudanogueira/32/7846_2.png) [@DudaNogueira](https://forum.weaviate.io/u/DudaNogueira)\
**Post date:** [April 29, 2024, 7:11pm UTC](https://forum.weaviate.io/t/oidc-configuration-weaviate/2099/6 "2024-04-29T19:11:12Z")

</div>

Hi @adithya.ch !

I was able to run weaviate using keycloak, but not sure this helps us here. 🤔

As far as I understood, you want to generate the token yourself and pass it to the client, right?

You have a valid point that if you want to change the apikey, you will need to restart the pods. However, this should not bring downtime, as you will have HA with multiple pods.

For storing the keys in values.yml, you may be able to use helm-secrets:

> **[GitHub - jkroepke/helm-secrets: A helm plugin that help manage secrets with...](https://github.com/jkroepke/helm-secrets)**
>
> A helm plugin that help manage secrets with Git workflow and store them anywhere - jkroepke/helm-secrets

Let me know if this helps. For new features in Weaviate, we advise opening a feature request in our repo:

> **[Build software better, together](https://github.com/weaviate/weaviate/issues/new/)**
>
> GitHub is where people build software. More than 100 million people use GitHub to discover, fork, and contribute to over 420 million projects.
