Uptimer v2.0.0-preview documentation — it describes the release candidate, and v1.8.0 remains the current release. Commands here pull the preview image :2.0.0-rc1. The Python SDK for this preview is a local wheel, not a PyPI release. Go to the current release (v1.8.0) →
Operating › Sign-in (OIDC)

Sign-in (OIDC)

Production sign-in with an OIDC provider, admins, and development sign-in.

Production sign-in is OIDC (authorization code with PKCE). Set:

SettingWhat it does
UPTIMER__AUTH__OIDC__ISSUER_URLthe provider’s issuer, exactly as its discovery document states it, trailing slash included
UPTIMER__AUTH__OIDC__CLIENT_IDthis installation’s client at the provider
UPTIMER__AUTH__OIDC__CLIENT_SECRETits secret
UPTIMER__AUTH__OIDC__REDIRECT_URLthe callback. Defaults to UPTIMER__GENERAL__SITE_URL + /ui/auth/oidc/callback
UPTIMER__AUTH__OIDC__ADMIN_SUBJECTScomma-separated provider subjects (sub) that are server admins
UPTIMER__AUTH__OIDC__END_SESSION_ENDPOINTlogout endpoint, when discovery names none
UPTIMER__AUTH__OIDC__POST_LOGOUT_REDIRECT_PARAMthe provider’s return-address parameter. Default post_logout_redirect_uri

The first three go together: setting only some of them refuses startup. Register the callback URL with the provider, and register <site>/ui/auth/login-required as an allowed logout return address.

When the callback URL is https://, the session and sign-in cookies are HTTPS-only. This holds behind a proxy that ends TLS, because it follows the configured address rather than the request.

Development sign-in (UPTIMER__AUTH__DEV=true) signs every visitor in as the shared Admin. It is off by default. uptimer dev turns it on unless UPTIMER__AUTH__DEV=false is set. Do not turn it on in production.