<a id="howto-oidc"></a>

# Configure single sign-on with OIDC

LXD uses [OpenID Connect (OIDC)](https://openid.net/developers/how-connect-works/) to authenticate users to the web UI and the CLI without storing local passwords. Instead, users are redirected to an external identity provider’s login page. For details about this process, refer to [OpenID Connect authentication](https://canonical.com/lxd/docs/latest/authentication/index.html.md#authentication-openid).

The following how-to guides provide detailed instructions for the SSO-based identity providers supported by LXD:

* [Configure Auth0](https://canonical.com/lxd/docs/latest/howto/oidc_auth0/index.html.md)
* [Configure Ory Hydra](https://canonical.com/lxd/docs/latest/howto/oidc_ory/index.html.md)
* [Configure Keycloak](https://canonical.com/lxd/docs/latest/howto/oidc_keycloak/index.html.md)
* [Configure Entra ID](https://canonical.com/lxd/docs/latest/howto/oidc_entra_id/index.html.md)
* [Configure Pocket ID](https://canonical.com/lxd/docs/latest/howto/oidc_pocket_id/index.html.md)
* [Configure authentik](https://canonical.com/lxd/docs/latest/howto/oidc_authentik/index.html.md)

## Related topics

How-to guides:

- [How to add remote servers](https://canonical.com/lxd/docs/latest/remotes/index.html.md#remotes)
- [How to expose LXD to the network](https://canonical.com/lxd/docs/latest/howto/server_expose/index.html.md#server-expose)

Explanation:

- [Remote API authentication](https://canonical.com/lxd/docs/latest/authentication/index.html.md#authentication)
