Authentication
Lynx Keycloak SSO
Single Sign-On for Lynx via Keycloak / generic OpenID Connect.
lynx_keycloak_sso
· v19.0.1.0.0
· Premium
What this solves
Lynx Keycloak SSO
Connect Lynx to Keycloak (or any standards-compliant OpenID Connect identity provider) for Single Sign-On, building on the shared lynx_sso_base framework so user provisioning, group mapping and audit logging are handled the same way as every other Lynx SSO connector.
The connector is fully configurable: point it at any realm issuer and let one-click discovery fill in the OIDC endpoints from the provider's .well-known/openid-configuration. It stays disabled until an administrator configures and enables a provider.
Key Features
One-click endpoint discovery - enter the realm issuer URL and the authorization, userinfo, token and end-session endpoints are filled in automatically from the provider metadata.
Standards-based OIDC login - works with Keycloak and any compliant OpenID Connect provider; the standard sub claim is mapped to the Odoo OAuth subject out of the box.
JIT user provisioning - first-login users are created (when enabled) and existing users are linked by email, reusing the lynx_sso_base provisioning framework.
Group mapping - map provider group claims to Odoo groups using the shared mapping primitives, with additive assignment that never strips a user's base access.
Audit logging - per-login events recorded through the shared SSO log for compliance review.
Integrates With
lynx_sso_base - shared SSO provisioning, mapping and logging.
auth_oauth - Odoo's OAuth substrate.
Depends on
Try Lynx Keycloak SSO on your team.
Free trial, no credit card. Talk to sales when you're ready.