Guides by topic
Choose a topic, narrow the document type, or filter by a name you already know. New to AuthCrunch? Follow the learning path for a complete local setup.
Identity providers
Connect local users, directories, and external identity providers.
- AWS CognitoGuide
Set up a Cognito user pool and client for login through the portal.
- DiscordGuide
Register a Discord application and filter access by guild membership and roles.
- FacebookGuide
Register a Facebook application and connect it to the portal using OAuth credentials.
- Generic OAuth providerReference
Find the generic OAuth provider example and its metadata and authorization URL settings.
- GitHubGuide
Register a GitHub application and configure login, callback URLs, and email claims.
- GitLabGuide
Connect GitLab.com or a self-hosted GitLab instance using an OAuth application.
Configure Google OAuth credentials, scopes, and the portal callback.
Create a JumpCloud SAML application and connect it to the authentication portal.
- KeycloakGuide
Configure a Keycloak realm, roles, groups, users, and a client for portal login.
- LDAP ConfigurationGuide
Connect an LDAP directory using the Microsoft Active Directory and POSIX configuration examples.
- LDAP user searchConcept
Understand LDAP binding, user search filters, and the directory lookup performed during login.
- LinkedInGuide
Register a LinkedIn application and configure its redirect URL and OAuth provider.
Configure a local identity store and connect its realm to the authentication portal.
- Local identity store formatReference
Inspect the local users.json structure, including password policy, user records, and revision metadata.
Connect Microsoft Entra ID using SAML application metadata and signing certificates.
- Microsoft OAuthGuide
Register a Microsoft application and configure OAuth login for Microsoft accounts.
- OAuth and OIDC providersConcept
Understand the external OAuth flow, PKCE, role claims, and provider button options.
- OAuth provider endpoint settingsReference
Configure OAuth provider startup delays, key retrieval retries, logout, and PKCE.
- OktaGuide
Register an Okta application and configure the portal callback and OAuth credentials.
- Ping IdentityGuide
Find the Ping Identity configuration example and provider setup screenshots.
- SAML identity providersConcept
Review SAML identity provider configuration and assertion time synchronization.
- Static UsersReference
Define local users, password hashes, and roles inside a Caddyfile identity store.
Login and MFA
Configure the portal, authentication challenges, and account enrollment.
Understand how the portal identifies a user and assembles authentication checkpoints.
Define the authentication challenges users must complete, including passwords, application codes, and hardware tokens.
Overview of the authentication portal, identity sources, and token-based connection to authorization.
Customize portal templates, styles, scripts, links, and login interface options.
- Internationalization (i18n)Reference
Set the portal language and find the translation messages used by the login interface.
- Local login sandboxConcept
Follow a local login through its sandbox session and password or MFA checkpoints.
Require multi-factor authentication for local users and enroll an authenticator application.
- User RegistrationGuide
Configure account registration, email verification, domain restrictions, and administrative approval.
Sessions and cookies
Understand tokens, browser cookies, redirects, and logout.
- Authentication cookiesReference
Configure the domain, path, and browser attributes of authentication cookies.
- Authorization redirectsReference
Configure how an authorization policy redirects unauthenticated requests to login.
- LogoutGuide
Configure trusted logout redirects and distinguish portal logout from provider logout.
- Token DiscoveryReference
Choose where an authorization policy looks for tokens and the order in which sources are checked.
- Token VerificationReference
Configure token signature verification with shared secrets, asymmetric keys, and key sources.
Limit the destinations accepted by login and logout redirects using domain and path trust rules.
Authorization
Decide who may access each application and pass identity to it.
Allow or deny requests using roles, claims, and ordered access control rules.
Authenticate protected requests using an API key issued by a local portal.
- Authorization overviewConcept
Overview of authorization policies, token checks, request identity, and access rules.
- Authorization policy syntaxReference
Look up authorization policy directives for keys, tokens, access rules, and request handling.
- Basic AuthenticationGuide
Authenticate protected requests with a username, password, and realm.
Exclude selected request paths from authorization with URI matching rules.
- Caddy PlaceholdersReference
Look up user metadata placeholders available to Caddy after authorization.
- Caddy User IdentityReference
Select which token field supplies the user identity returned to Caddy.
- Identity headersReference
Pass token claims to downstream applications in HTTP headers and strip authentication data.
- IP Address FilteringReference
Match the source address of a request against the IP address recorded in its token.
- Path-Based Access ListsReference
Check a request path against access lists carried in token claims.
- Protect your first appTutorial
Run a local AuthCrunch portal and protect a response with a role-based policy, using a complete tested Caddyfile.
- User TransformsReference
Map identity claims to roles, login requirements, portal links, and access decisions.
- Verify accessTutorial
Test unauthenticated redirects, allowed and denied users, and logout in the local AuthCrunch walkthrough.
Applications and SSO
Integrate applications with AuthCrunch and identity protocols.
- Angular integration librariesReference
Find Angular libraries for portal redirects and an avatar menu.
Configure AuthCrunch as a SAML identity provider for access to the AWS console.
Find an example that protects Prometheus, Alertmanager, and Elasticsearch with local, LDAP, and GitHub identities.
Operations
Install, manage credentials and messaging, and diagnose your setup.
- API OverviewReference
Find the portal, profile, server, and system API families and their intended callers.
- Community examplesReference
Find community-written examples of AuthCrunch integrations.
- Generate an ECDSA keyReference
Generate an ECDSA P-256 private key using OpenSSL.
- Install and verifyTutorial
Get the published AuthCrunch bundle, verify its security modules, and prepare a local learning environment.
Generate local password hashes with authdbctl and change passwords through the portal settings.
- Messaging ProvidersReference
Configure email and file messaging providers for verification codes and account workflows.
- Next stepsGuide
Choose an identity provider, add authentication controls, and understand what must change before deploying the local example.
- Portal APIReference
Use JSON requests to log in and inspect the current portal identity and session.
- Portal operations notesReference
Notes on privileged ports, source IP tracking, and authentication portal configuration details.
- Secrets ManagementReference
Configure named credentials and secret manager integrations for AuthCrunch services.
- Server APIReference
Inspect and manage portal runtime state and user data through administrative API endpoints.
- Start hereConcept
Learn how AuthCrunch connects login to application access, then build and verify your first local setup.
- System APIReference
Review communication between portals and gatekeepers, including state synchronization and revocation lists.
- TroubleshootTroubleshooting
Diagnose missing security modules, local startup failures, login redirects, and denied access in AuthCrunch.