9
Feature Request: Map OIDC group claims to Collections (post-authentication)
Source: dani-garcia/vaultwarden#7141 · opened by @DenisKoether
Describe the feature When using OIDC SSO (e.g. via Authentik), group information is already included in the ID token (groups claim). However, Vaultwarden currently ignores these claims entirely. It would be useful to support optional mapping of OIDC group claims to Vaultwarden Collections (or organization memberships) after successful authentication. --- Current behavior • OIDC login works correctly • User is created (if enabled) • Group claims (e.g. groups) are ignored • Collection membership must be managed manually inside Vaultwarden --- Expected behavior After a successful OIDC login: • Vaultwarden reads group claims from the ID token (e.g. groups) • A configurable mapping is applied, e.g.: • User is automatically assigned to the corresponding collections This should be: • Optional (disabled by default) • Configurable (mapping table or environment config) • Applied only after …
No pledges yet. Be the first to back this.
Comments
Similar requests
[duplicate] As my user has "manager" role on multiple collections, I want to invite a user to multiple collections at once
1 vote · 0 comments
Deleting a collection - Backend says Yes, Frontend says No. Can we fix that?
1 vote · 0 comments
Right to invite new users without accessing all collections
3 votes · 0 comments
Use "name" claim in OIDC SSO for display name
5 votes · 0 comments
[Feature request] Scoped, metadata-only API for AI agents managing collections/groups
1 vote · 0 comments
No comments yet.