Create an authentik OAuthProvider (via OIDC discovery)
Source:R/providers__research_enterprise.R
oauth_provider_authentik.RdConfigure login for an authentik OAuth2/OIDC application. Supply the
instance URL and application slug, then pass the registered credentials
to oauth_client() with the scopes configured in authentik.
Usage
oauth_provider_authentik(
base_url,
application_slug,
name = "authentik",
token_auth_style = NULL
)Arguments
- base_url
authentik instance URL, for example
"https://auth.example.com".- application_slug
Application slug configured in authentik (not the display name or client ID).
- name
Optional provider name (default
"authentik").- token_auth_style
Authentication style for token requests: "header" (client_secret_basic), "body" (client_secret_post), or "public" (public client; send
client_idonly). The alias"none"is also accepted for"public". If NULL (default), it is inferred conservatively from discovery:"header"(client_secret_basic) is preferred, followed by"body"(client_secret_post), then"public"ifnoneis advertised and PKCE is enabled. Settoken_auth_style = "public"explicitly for a public client registration. JWT methods ("client_secret_jwt","private_key_jwt") and mTLS methods ("tls_client_auth","self_signed_tls_client_auth") must be selected explicitly. Seeoauth_provider()for the supported methods and their credentials.
Value
OAuthProvider object configured for the authentik application.
Details
Uses authentik's default per-application issuer mode and preserves its
trailing slash. Global issuer mode is not supported by this preset;
configure the endpoints explicitly with oauth_provider() for that mode.
For refresh tokens, both request "offline_access" and enable the
corresponding scope mapping in authentik. Configure a signing key that
supports RS256 for OIDC discovery.
See authentik's provider guide.