# How to use single-sign on

**URL:** https://forum.yunohost.org/t/how-to-use-single-sign-on/43069
**Category:** Discuss
**Tags:** english
**Created:** [September 25, 2026, 8:58pm UTC](https://forum.yunohost.org/t/how-to-use-single-sign-on/43069 "2026-09-25T20:58:03Z")
**Posts on this page:** 14
**Page:** 1

<div class="post-metadata">

### Author: ![brainchild](https://forum.yunohost.org/user_avatar/forum.yunohost.org/brainchild/32/13982_2.png) [@brainchild](https://forum.yunohost.org/u/brainchild)
#### Post date: [September 25, 2026, 8:58pm UTC](https://forum.yunohost.org/t/how-to-use-single-sign-on/43069/1 "2026-09-25T20:58:03Z")

</div>

I am new to Yunohost, and find myself quite confused about single sign-on. Having now tried several different applications, I find that for each, login requires credentials being entered into a login page generated by the application, and also that the credentials accepted are those managed by the application. Separate login to the portal is also required.

An [issue report](https://github.com/YunoHost/issues/issues/2880) that I previously created explains the details of my overall confusion.

Although the report was intended to prompt discussion over the behavior that would be desired, I am also trying to learn the actual behavior, from the current design, of single sign-on in Yunohost.

One of my observations was that the characterization as single sign-on may be referring to behavior that is more correctly described as same sign-on. However, I have still not observed even any functionality for same sign-on.

I am hoping someone could explain how to use single sign-on in Yunohost.

---

<div class="post-metadata">

### Author: ![jarod5001](https://forum.yunohost.org/user_avatar/forum.yunohost.org/jarod5001/32/5323_2.png) [@jarod5001](https://forum.yunohost.org/u/jarod5001)
#### Post date: [September 26, 2026, 11:43am UTC](https://forum.yunohost.org/t/how-to-use-single-sign-on/43069/2 "2026-09-26T11:43:33Z")

</div>

To explain it simply :

- every user has an account on yunohost is managed by ldap, so when you login to the portal you use your credentials
- some apps support only ldap, so you have to login in the app using your yunohost credentials regardless you are logged in to the portal or not, these apps have their own login mechanism but will use ldap as authentication backend
- some apps support sso, these apps get the username passed via http header. So when you login to the portal, you are automatically logged in to the app
- some apps do not support neither, so they will rely on their own authentication

You can check if the app supports ldap or sso or both or none if you expand the section “yunohost integration” in the webadmin (at the bottom of the app details page). You can also dive into the package of each app and check the manifest

---

<div class="post-metadata">

### Author: ![tmb](https://forum.yunohost.org/letter_avatar_proxy/v4/letter/t/7c8e57/32.png) [@tmb](https://forum.yunohost.org/u/tmb)
#### Post date: [September 26, 2026, 6:57pm UTC](https://forum.yunohost.org/t/how-to-use-single-sign-on/43069/3 "2026-09-26T18:57:39Z")

</div>

> [@jarod5001](#):
>
> You can also dive into the package of each app and check the manifest

Would be good if the app-catalog could filter for SSO/LDAP.

---

<div class="post-metadata">

### Author: ![brainchild](https://forum.yunohost.org/user_avatar/forum.yunohost.org/brainchild/32/13982_2.png) [@brainchild](https://forum.yunohost.org/u/brainchild)
#### Post date: [September 27, 2026, 1:08am UTC](https://forum.yunohost.org/t/how-to-use-single-sign-on/43069/4 "2026-09-27T01:08:02Z")

</div>

Thank you for the clear explanation.

Unfortunately, I have already tried several applications that are reported to support for SSO, but in each case, the application generates a login screen, regardless of the portal login, and also fails to accept the credentials accepted by Yunohost.

In one case, I submitted a report to the package maintainer, but I am still waiting for a response.

Adding to the confusion, the language appearing in the application details is “Single sign-on is available (SSO)”. The phrasing implies that additional action may be required in order to use SSO, even though no instructions are provided. If SSO will function without any additional configuration, then some different phrasing would be more helpful.

---

<div class="post-metadata">

### Author: ![otm33](https://forum.yunohost.org/user_avatar/forum.yunohost.org/otm33/32/11941_2.png) [@otm33](https://forum.yunohost.org/u/otm33)
#### Post date: [September 27, 2026, 2:10am UTC](https://forum.yunohost.org/t/how-to-use-single-sign-on/43069/5 "2026-09-27T02:10:53Z")

</div>

Do you remember which application(s) it was?

---

<div class="post-metadata">

### Author: ![brainchild](https://forum.yunohost.org/user_avatar/forum.yunohost.org/brainchild/32/13982_2.png) [@brainchild](https://forum.yunohost.org/u/brainchild)
#### Post date: [September 27, 2026, 2:59am UTC](https://forum.yunohost.org/t/how-to-use-single-sign-on/43069/6 "2026-09-27T02:59:14Z")

</div>

I have tried Vaultwarden and Roundcube.

I have also tried SnappyMail, but it may have a more fundamental problem. Trying to open the administrative interface results in an error message being displayed in the browser.

I submitted a report for Vaultwarden.

---

<div class="post-metadata">

### Author: ![otm33](https://forum.yunohost.org/user_avatar/forum.yunohost.org/otm33/32/11941_2.png) [@otm33](https://forum.yunohost.org/u/otm33)
#### Post date: [September 27, 2026, 3:47pm UTC](https://forum.yunohost.org/t/how-to-use-single-sign-on/43069/7 "2026-09-27T15:47:11Z")

</div>

Well… afaik, vaultwarden cannot work with yunohost sso : it’s meant to be used with an OIDC provider -dex, keycloak…- (indeed “sso = true” should ne changed to “sso = false” in the manifest).

SSO works without tweaking with snappymail if the app is installed on the main domain. If it is installed on a subdomain, adding

```auto
secfetch_allow = "dest=document,mode=navigate,site=same-site"

```

to the

```auto
/var/www/snappymail/app/data/_data_/_default_/configs/application.ini

```

should fix the issue with SSO. See [here](https://forum.yunohost.org/t/probleme-de-domaines-le-sso-semmele/42873/5).

With roundcube, do you remember what was the issue ?

---

<div class="post-metadata">

### Author: ![brainchild](https://forum.yunohost.org/user_avatar/forum.yunohost.org/brainchild/32/13982_2.png) [@brainchild](https://forum.yunohost.org/u/brainchild)
#### Post date: [September 27, 2026, 9:10pm UTC](https://forum.yunohost.org/t/how-to-use-single-sign-on/43069/8 "2026-09-27T21:10:15Z")

</div>

> [@otm33](#):
>
> Well… afaik, vaultwarden cannot work with yunohost sso : it’s meant to be used with an OIDC provider

It is quite a shame that OIDC is not yet included in Yunohost.

Would it be inadvisable to connect the installed instance of Vaultwarden to an already existing OIDC provider?

> [@otm33](#):
>
> SSO works without tweaking with snappymail if the app is installed on the main domain. If it is installed on a subdomain, adding… should fix the issue with SSO.

I really wish requirements of such kind were documented, if not automated.

> [@otm33](#):
>
> With roundcube, do you remember what was the issue ?

When the login page of Roundcube is first loaded, a message is shown, “_Login failed._” At this stage, no credentials have actually been submitted. The message appears in this way simply from navigating to the base path of the application, with no additional path components or any query parameters, from a fresh browser window. A login session for the portal has already been established. Otherwise, it will be prompted.

Upon submission of the credentials that are the same as those accepted by Yunohost, the login page simply reloads, and again flashes the same message, “_Login failed._”

---

<div class="post-metadata">

### Author: ![otm33](https://forum.yunohost.org/user_avatar/forum.yunohost.org/otm33/32/11941_2.png) [@otm33](https://forum.yunohost.org/u/otm33)
#### Post date: [September 27, 2026, 9:33pm UTC](https://forum.yunohost.org/t/how-to-use-single-sign-on/43069/9 "2026-09-27T21:33:14Z")

</div>

> [@brainchild](#):
>
> Would it be inadvisable to connect the installed instance of Vaultwarden to an already existing OIDC provider?

You can use [dex](https://apps.yunohost.org/app/dex).

> [@brainchild](#):
>
> When the login page of Roundcube is first loaded, a message is shown, “_Login failed._” At this stage, no credentials have actually been submitted. The message appears in this way simply from navigating to the base path of the application, with no additional path components or any query parameters, from a fresh browser window. A login session for the portal has already been established. Otherwise, it will be prompted.
> 
> Upon submission of the credentials that are the same as those accepted by Yunohost, the login page simply reloads, and again flashes the same message, “_Login failed._”

Yes, that is indeed strange because SSO does work with this app. Is it a fresh install ?

---

<div class="post-metadata">

### Author: ![otm33](https://forum.yunohost.org/user_avatar/forum.yunohost.org/otm33/32/11941_2.png) [@otm33](https://forum.yunohost.org/u/otm33)
#### Post date: [September 27, 2026, 9:35pm UTC](https://forum.yunohost.org/t/how-to-use-single-sign-on/43069/10 "2026-09-27T21:35:39Z")

</div>

> [@otm33](#):
>
> You can use [dex](https://apps.yunohost.org/app/dex).

See here :

> [@Vaulltwarden + DEX: SSO login FIX (Single Sign On)](https://forum.yunohost.org/t/vaulltwarden-dex-sso-login-fix-single-sign-on/41879):
>
> What app is this about, and its version: Vaultwarden + DEX What YunoHost version are you running: 12.1.39 What type of hardware are you using: Old laptop or computer Describe your issue Vaultwarden SSO with YunoHost Dex — Fix for “invalid\_client” error If you get Failed to contact token endpoint: invalid\_client when trying to use SSO in Vaultwarden with YunoHost’s Dex, the cause is SSOwat stripping the Basic Auth header before it reaches Dex. This is an anti-spoofing protection built into Yu…

Hope this helps.

---

<div class="post-metadata">

### Author: ![brainchild](https://forum.yunohost.org/user_avatar/forum.yunohost.org/brainchild/32/13982_2.png) [@brainchild](https://forum.yunohost.org/u/brainchild)
#### Post date: [September 27, 2026, 10:15pm UTC](https://forum.yunohost.org/t/how-to-use-single-sign-on/43069/11 "2026-09-27T22:15:43Z")

</div>

> [@otm33](#):
>
> You can use [dex](https://apps.yunohost.org/app/dex).

I was considering using an existing, external provider.

Am I understanding correctly, that Dex would function as an intermediary, by providing OIDC authentication against the users and credentials managed by Yunohost?

> [@otm33](#):
>
> Is it a fresh install ?

Yes.

---

<div class="post-metadata">

### Author: ![otm33](https://forum.yunohost.org/user_avatar/forum.yunohost.org/otm33/32/11941_2.png) [@otm33](https://forum.yunohost.org/u/otm33)
#### Post date: [September 27, 2026, 11:35pm UTC](https://forum.yunohost.org/t/how-to-use-single-sign-on/43069/12 "2026-09-27T23:35:31Z")

</div>

> [@brainchild](#):
>
> I was considering using an existing, external provider.

Yes, that’s also possible.

> [@brainchild](#):
>
> Am I understanding correctly, that Dex would function as an intermediary, by providing OIDC authentication against the users and credentials managed by Yunohost?

Yes, dex will use yunohost ldap.

> [@brainchild](#):
>
> > [@otm33](#):
> >
> > Is it a fresh install ?
> 
> Yes.

I guess you already have tried to force the upgrade or uninstall-reinstall ?

---

<div class="post-metadata">

### Author: ![brainchild](https://forum.yunohost.org/user_avatar/forum.yunohost.org/brainchild/32/13982_2.png) [@brainchild](https://forum.yunohost.org/u/brainchild)
#### Post date: [September 28, 2026, 3:46am UTC](https://forum.yunohost.org/t/how-to-use-single-sign-on/43069/13 "2026-09-28T03:46:11Z")

</div>

> [@otm33](#):
>
> I guess you already have tried to force the upgrade or uninstall-reinstall ?

Yes. I have tried both, but the same problem still persists.

---

<div class="post-metadata">

### Author: ![brainchild](https://forum.yunohost.org/user_avatar/forum.yunohost.org/brainchild/32/13982_2.png) [@brainchild](https://forum.yunohost.org/u/brainchild)
#### Post date: [September 28, 2026, 10:31pm UTC](https://forum.yunohost.org/t/how-to-use-single-sign-on/43069/14 "2026-09-28T22:31:03Z")

</div>

I have created a [new thread](https://forum.yunohost.org/t/login-failing-for-roundcube/43087) to discuss the login failures in Roundcube.
