Evaluate Vaultwarden OIDC SSO (upstream support landed in 1.34) #122
Labels
No labels
audit-work
bug
docs
general-admin
major-upgrade
needs-vps-sync
new-service
on-hold
outside-work
post-podman
renovate
upstream
vps
No milestone
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
mysticalsoap/docker#122
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The OIDC exclusion reasoning in Auth-and-Security.md predates Vaultwarden shipping SSO: upstream added OpenID Connect support in 1.34.0 (2025,
SSO_ENABLED, marked experimental at release). Master password still does vault decryption — SSO replaces authentication only, so this is the same enforcement-point move the other OIDC clients got, not a key-escrow change.To evaluate before committing:
/adminarrangement changesone_factorfriend-tier like RxResume/Lychee, ortwo_factorgiven what it protectsExclusion lists go stale — this is the periodic re-verify.