DocumentationConfiguration

Rust · 0.1.0

Authentication

Use account sign-in, SSO and API tokens for their intended roles.

Browser sign-in

The browser supports password sign-in and configured OAuth2 identity providers. Sign-in returns an access token and sets a refresh cookie; refresh obtains a new short-lived access token. Use HTTPS for remote access. Provider client IDs, secrets and redirect URLs must agree with the identity provider and your external instance origin.

Administrative recovery

Before disabling ordinary password sign-in, verify a separate administrator recovery path and test SSO with a non-administrator account. Deployment-managed provider settings cannot be changed through the UI while their file override is active. Removing an identity provider is not the same as unlinking one user's identity; review linked identities.

Automation credentials

Use a personal access token for an authorized integration rather than a password embedded in a script. Treat tokens as secrets, send them only to the intended instance over HTTPS, and revoke them when the integration no longer needs access. See API access.

Set up OAuth2 without losing administrator access

Keep your working administrator session open. The administrator password sign-in screen is /auth/admin on your application origin; test it in a separate signed-out session before changing ordinary sign-in policy. In Settings → SSO create a provider with a stable identifier and display name. Supply Client ID, Client secret, authorization URL, token URL, user-info URL, scopes and field mappings from that provider’s own documentation. The identifier field mapping must identify a stable external account, not a mutable display name.

Register the callback and test the whole flow

For an instance at https://notes.example.com, the browser callback is https://notes.example.com/auth/callback. Register that exact URL at the provider. Save the provider, then use a separate ordinary account/session to complete provider sign-in and return to Memos. If new SSO users should be created, check the registration policy as well. Only after this succeeds should you consider disabling ordinary password sign-in. Callback mismatch errors require correcting origin/path at the provider; an empty provider list or deployment-managed write error requires administrator configuration work.