How to Configure OIDC_ONLY Mode for SSO-Only Authentication in TREK
Set OIDC_ONLY=true in your environment variables to disable local password login and enforce OpenID Connect authentication exclusively, with the first SSO user automatically becoming the admin.
TREK is an open-source platform that supports running in strict "SSO-only" mode, completely eliminating local username and password authentication in favor of OpenID Connect (OIDC). This configuration is controlled exclusively through the OIDC_ONLY environment variable and requires a properly configured identity provider.
What OIDC_ONLY Mode Disables and Enables
When you configure OIDC_ONLY=true, TREK makes three critical architectural changes to the authentication flow:
-
Password authentication is completely disabled – The local login and registration forms are removed from the UI, and the backend rejects password-based authentication attempts. The admin panel displays a notice indicating these settings are managed by
OIDC_ONLYand cannot be changed at runtime. -
OIDC provider becomes mandatory – The system requires valid
OIDC_ISSUERandOIDC_CLIENT_IDenvironment variables (and optionallyOIDC_CLIENT_SECRET) to start. Without these, the SSO-only mode cannot function. -
Automatic admin provisioning – On a fresh installation with no existing users, the first successful authentication via your identity provider (IdP) is automatically granted administrator privileges, eliminating the need to create a local admin account first.
Prerequisites for Enabling OIDC_ONLY
Before activating SSO-only mode, ensure you have:
- A functional OpenID Connect provider (such as Auth0, Keycloak, or Azure AD)
- The OIDC discovery endpoint URL (
OIDC_ISSUER) - Client credentials registered with your provider (
OIDC_CLIENT_IDand optionallyOIDC_CLIENT_SECRET) - The public base URL of your TREK instance (
APP_URL) for constructing redirect URIs
Step-by-Step Configuration
Configure Environment Variables
Add the following to your .env file or environment configuration:
# Required OIDC endpoints
OIDC_ISSUER=https://auth.example.com
OIDC_CLIENT_ID=trek
OIDC_CLIENT_SECRET=supersecret
# Enable SSO-only mode
OIDC_ONLY=true
# Public URL for callback handling
APP_URL=https://trek.example.com
Note that OIDC_ONLY is read at server startup from process.env.OIDC_ONLY and cannot be toggled from the Admin UI.
Docker Compose Setup
In your docker-compose.yml, pass the variables to the container:
services:
app:
image: mauriceboe/trek:latest
environment:
- OIDC_ISSUER=https://auth.example.com
- OIDC_CLIENT_ID=trek
- OIDC_CLIENT_SECRET=supersecret
- OIDC_ONLY=true
- APP_URL=https://trek.example.com
Kubernetes Helm Deployment
For Kubernetes installations using the TREK Helm chart, modify your values.yaml:
env:
OIDC_ISSUER: https://auth.example.com
OIDC_CLIENT_ID: trek
OIDC_CLIENT_SECRET: supersecret
OIDC_ONLY: "true"
APP_URL: https://trek.example.com
How the Authentication Logic Works
The enforcement of SSO-only mode occurs in server/src/services/authService.ts, where the application checks the flag at runtime:
// server/src/services/authService.ts
const oidcOnlyEnabled =
process.env.OIDC_ONLY?.toLowerCase() === 'true' || get('oidc_only') === 'true';
...
env_override_oidc_only: process.env.OIDC_ONLY === 'true',
Because the flag is evaluated against process.env.OIDC_ONLY directly, the server must be restarted for changes to take effect. The configuration is also exposed to the frontend to conditionally render the SSO-only interface.
Verifying Your SSO-Only Setup
After restarting the TREK server with the new configuration:
- Navigate to the login page and confirm that only the SSO button is visible
- Verify that username and password fields are completely absent
- Attempt to log in via your IdP
- Confirm that the first successful login grants administrator access to that user
Summary
- Environment-only setting:
OIDC_ONLYmust be set as an environment variable; it cannot be changed through the Admin UI. - Complete lockout: Local password login and registration are disabled when the flag is set to
true. - Automatic admin: The first user to authenticate via SSO becomes the admin on fresh installations.
- Required variables:
OIDC_ISSUER,OIDC_CLIENT_ID, andAPP_URLare mandatory when OIDC_ONLY is enabled.
Frequently Asked Questions
Can I switch OIDC_ONLY on and off from the Admin UI?
No. According to the source code in server/src/services/authService.ts, OIDC_ONLY is strictly an environment-variable-only setting. The value is read at server startup and cannot be modified at runtime through the admin panel. You must restart the TREK server after changing this variable.
What happens if I enable OIDC_ONLY without configuring an OIDC provider?
TREK requires valid OIDC_ISSUER and OIDC_CLIENT_ID values when OIDC_ONLY is enabled. Without these, the authentication system will not function properly, and users will be unable to access the application since both local and SSO authentication paths would be unavailable or misconfigured.
How is the first admin account created when using OIDC_ONLY?
On a fresh installation with no existing users, TREK automatically promotes the first successful SSO authentication to administrator status. This eliminates the traditional bootstrap process of creating a local admin account; simply configure your IdP and log in to claim admin rights.
Is OIDC_CLIENT_SECRET required for all OIDC providers?
No. The OIDC_CLIENT_SECRET is optional and depends on your specific provider's configuration. Some providers, particularly those using public clients or PKCE flows, may not require a client secret. However, OIDC_ISSUER and OIDC_CLIENT_ID are always mandatory when OIDC_ONLY is enabled.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →