Skip to content

External login (OIDC)

Day Planner can offer a Sign in with {provider} button next to email and password, using any OpenID Connect (OIDC) provider: Clerk, Authentik, Keycloak, Google and others.

In your provider, create an OAuth or OIDC application:

  • Scopes: openid email profile
  • Redirect URI: {BETTER_AUTH_URL}/api/auth/callback/{OIDC_PROVIDER_ID}

For example, with BETTER_AUTH_URL=https://tasks.example.com and OIDC_PROVIDER_ID=authentik, the redirect URI is https://tasks.example.com/api/auth/callback/authentik.

Copy the client ID, client secret and the discovery URL (it ends in /.well-known/openid-configuration).

Terminal window
OIDC_DISCOVERY_URL=https://id.example.com/application/o/day-planner/.well-known/openid-configuration
OIDC_CLIENT_ID=change-me
OIDC_CLIENT_SECRET=change-me
OIDC_PROVIDER_ID=authentik
OIDC_PROVIDER_NAME=Authentik

Set all three of the URL and client settings, or none; the app shows Configuration needed if only some are set. Restart, and the sign-in page shows Sign in with Authentik.

When someone signs in with the provider for the first time:

  • Their email has no account yet: a new account is created, if the sign-up policy is open. Otherwise the sign-in is refused.
  • An account with that email exists: the provider login is linked to it only if the provider says the email is verified and the Day Planner account’s email is verified too. This stops someone who registers your address elsewhere from taking over your account.

If linking is refused, the person sees account_not_linked.

Clerk works as an OIDC provider from a production Clerk instance. In the Clerk dashboard, add an OAuth application with the scopes and redirect URI listed in this guide, then use its discovery URL. Clerk development instances can’t complete the browser flow, because they keep sessions on a different domain.