Guides by topic
Choose a topic, narrow the document type, or filter by a name you already know. New to AuthCrunch? Follow the learning path for a complete local setup.
Identity providers
Connect local users, directories, and external identity providers.
- AWS CognitoGuide
Set up a Cognito user pool and client for login through the portal.
- DiscordGuide
Register a Discord application and filter access by guild membership and roles.
- FacebookGuide
Register a Facebook application and connect it to the portal using OAuth credentials.
- Generic OpenID ConnectReference
Connect an OIDC service through discovery, validate provider tokens, map groups to application roles, and troubleshoot missing claims.
- GitHubGuide
Add GitHub login to an AuthCrunch portal, grant access by numeric account ID or public organization membership, and troubleshoot callbacks and email claims.
- GitLabGuide
Sign in with GitLab.com or GitLab Self-Managed, filter group paths from UserInfo, and verify application access.
- Google sign-inGuide
Register a Google web client, grant application access by account ID, and understand Workspace domain and Cloud Identity group limits.
Create a JumpCloud SAML application and connect it to the authentication portal.
- KeycloakGuide
Connect a Keycloak realm to AuthCrunch, map group membership into the ID token, and verify allowed and denied application access.
- LDAP ConfigurationGuide
Connect an LDAP directory using the Microsoft Active Directory and POSIX configuration examples.
- LDAP user searchConcept
Understand LDAP binding, user search filters, and the directory lookup performed during login.
- LinkedInGuide
Register a LinkedIn application and configure its redirect URL and OAuth provider.
Configure a local identity store and connect its realm to the authentication portal.
- Local identity store formatReference
Inspect the local users.json structure, including password policy, user records, and revision metadata.
- Microsoft Entra IDGuide
Connect an Entra tenant, map app roles to protected application access, and handle missing email, group overage, and Microsoft account types.
Connect Microsoft Entra ID using SAML application metadata and signing certificates.
- OAuth and OIDC providersConcept
Connect an external identity provider to the portal, choose callback URLs and scopes, and turn identity claims into application permissions.
- OAuth provider endpoint settingsReference
Configure OAuth provider startup delays, key retrieval retries, logout, and PKCE.
- OktaGuide
Use an Okta custom authorization server, include an ID-token groups claim, and restrict an AuthCrunch application to an assigned group.
- Ping IdentityGuide
Find the Ping Identity configuration example and provider setup screenshots.
- SAML identity providersConcept
Review SAML identity provider configuration and assertion time synchronization.
- Static UsersReference
Define local users, password hashes, and roles inside a Caddyfile identity store.
Login and MFA
Configure the portal, authentication challenges, and account enrollment.
Understand how the portal identifies a user and assembles authentication checkpoints.
Define the authentication challenges users must complete, including passwords, application codes, and hardware tokens.
Overview of the authentication portal, identity sources, and token-based connection to authorization.
Customize portal templates, styles, scripts, links, and login interface options.
- Internationalization (i18n)Reference
Set the portal language and find the translation messages used by the login interface.
- Local login sandboxConcept
Follow a local login through its sandbox session and password or MFA checkpoints.
Require multi-factor authentication for local users and enroll an authenticator application.
- User RegistrationGuide
Configure account registration, email verification, domain restrictions, and administrative approval.
Sessions and cookies
Understand tokens, browser cookies, redirects, and logout.
- Authentication cookiesReference
Configure the domain, path, and browser attributes of authentication cookies.
- Authorization redirectsReference
Configure how an authorization policy redirects unauthenticated requests to login.
- LogoutGuide
Configure trusted logout redirects and distinguish portal logout from provider logout.
- Token DiscoveryReference
Choose where an authorization policy looks for tokens and the order in which sources are checked.
- Token VerificationReference
Configure token signature verification with shared secrets, asymmetric keys, and key sources.
Limit the destinations accepted by login and logout redirects using domain and path trust rules.
Authorization
Decide who may access each application and pass identity to it.
Allow or deny requests using roles, claims, and ordered access control rules.
Authenticate protected requests using an API key issued by a local portal.
- Authorization overviewConcept
Overview of authorization policies, token checks, request identity, and access rules.
- Authorization policy syntaxReference
Look up authorization policy directives for keys, tokens, access rules, and request handling.
- Basic AuthenticationGuide
Authenticate protected requests with a username, password, and realm.
Exclude selected request paths from authorization with URI matching rules.
- Caddy PlaceholdersReference
Look up user metadata placeholders available to Caddy after authorization.
- Caddy User IdentityReference
Select which token field supplies the user identity returned to Caddy.
- Identity headersReference
Pass token claims to downstream applications in HTTP headers and strip authentication data.
- IP Address FilteringReference
Match the source address of a request against the IP address recorded in its token.
- Path-Based Access ListsReference
Check a request path against access lists carried in token claims.
- Protect your first appTutorial
Run a local AuthCrunch portal and protect a response with a role-based policy, using a complete tested Caddyfile.
- User TransformsReference
Map identity claims to roles, login requirements, portal links, and access decisions.
- Verify accessTutorial
Test unauthenticated redirects, allowed and denied users, and logout in the local AuthCrunch walkthrough.
Applications and SSO
Integrate applications with AuthCrunch and identity protocols.
- Angular integration librariesReference
Find Angular libraries for portal redirects and an avatar menu.
Configure AuthCrunch as a SAML identity provider for access to the AWS console.
Find an example that protects Prometheus, Alertmanager, and Elasticsearch with local, LDAP, and GitHub identities.
Operations
Install, manage credentials and messaging, and diagnose your setup.
- API OverviewReference
Find the portal, profile, server, and system API families and their intended callers.
- Community examplesReference
Find community-written examples of AuthCrunch integrations.
- Generate an ECDSA keyReference
Generate an ECDSA P-256 private key using OpenSSL.
- Install and verifyTutorial
Get the published AuthCrunch bundle, verify its security modules, and prepare a local learning environment.
Generate local password hashes with authdbctl and change passwords through the portal settings.
- Messaging ProvidersReference
Configure email and file messaging providers for verification codes and account workflows.
- Next stepsGuide
Choose an identity provider, add authentication controls, and understand what must change before deploying the local example.
- Portal APIReference
Use JSON requests to log in and inspect the current portal identity and session.
- Portal operations notesReference
Notes on privileged ports, source IP tracking, and authentication portal configuration details.
- Secrets ManagementReference
Configure named credentials and secret manager integrations for AuthCrunch services.
- Server APIReference
Inspect and manage portal runtime state and user data through administrative API endpoints.
- Start hereConcept
Learn how AuthCrunch connects login to application access, then build and verify your first local setup.
- System APIReference
Review communication between portals and gatekeepers, including state synchronization and revocation lists.
- TroubleshootTroubleshooting
Diagnose missing security modules, local startup failures, login redirects, and denied access in AuthCrunch.