External login (OIDC)
Day Planner can offer a Sign in with {provider} button next to email and password, using any OpenID Connect (OIDC) provider: Clerk, Authentik, Keycloak, Google and others.
Register Day Planner with the provider
Section titled “Register Day Planner with the provider”In your provider, create an OAuth or OIDC application:
- Scopes:
openid email profile - Redirect URI:
{BETTER_AUTH_URL}/api/auth/callback/{OIDC_PROVIDER_ID}
For example, with BETTER_AUTH_URL=https://tasks.example.com and OIDC_PROVIDER_ID=authentik, the redirect URI is https://tasks.example.com/api/auth/callback/authentik.
Copy the client ID, client secret and the discovery URL (it ends in /.well-known/openid-configuration).
Configure Day Planner
Section titled “Configure Day Planner”OIDC_DISCOVERY_URL=https://id.example.com/application/o/day-planner/.well-known/openid-configurationOIDC_CLIENT_ID=change-meOIDC_CLIENT_SECRET=change-meOIDC_PROVIDER_ID=authentikOIDC_PROVIDER_NAME=AuthentikSet all three of the URL and client settings, or none; the app shows Configuration needed if only some are set. Restart, and the sign-in page shows Sign in with Authentik.
How accounts are matched
Section titled “How accounts are matched”When someone signs in with the provider for the first time:
- Their email has no account yet: a new account is created, if the sign-up policy is open. Otherwise the sign-in is refused.
- An account with that email exists: the provider login is linked to it only if the provider says the email is verified and the Day Planner account’s email is verified too. This stops someone who registers your address elsewhere from taking over your account.
If linking is refused, the person sees account_not_linked.
Using Clerk as the provider
Section titled “Using Clerk as the provider”Clerk works as an OIDC provider from a production Clerk instance. In the Clerk dashboard, add an OAuth application with the scopes and redirect URI listed in this guide, then use its discovery URL. Clerk development instances can’t complete the browser flow, because they keep sessions on a different domain.
See also
Section titled “See also”- How sign-in and API keys work: accounts, sessions and linking
- Account not linked: when a provider login is refused
- Configuration: the
OIDC_settings