You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何配置Flask-pyoidc等Python OpenID Connect模块适配IBM Cloud App ID?

Configuring Flask-pyoidc with IBM Cloud App ID

I've worked through this exact scenario before, so let's break down how to map IBM Cloud App ID's OpenID Connect (OIDC) parameters to Flask-pyoidc's configuration. The key is leveraging App ID's standard OIDC metadata endpoint to avoid manual endpoint typos, but I'll cover both automatic discovery and manual configuration just in case.

Step 1: Grab Your App ID Credentials & Metadata

First, log into your IBM Cloud console and navigate to your App ID service instance. Collect these values from the Credentials or Applications tab:

  • Tenant ID: Unique identifier for your App ID instance (found under "Service Credentials" or in the instance URL)
  • Region: The geographic region where your App ID is hosted (e.g., us-south, eu-gb, au-syd)
  • Client ID: The client ID for your registered application
  • Client Secret: The client secret paired with your client ID
  • Redirect URI: The callback URL for your Flask app (must be pre-configured in the App ID "Applications" tab)

App ID exposes all its OIDC endpoints via a well-known metadata URL:

https://<REGION>.appid.cloud.ibm.com/oauth/v4/<TENANT_ID>/.well-known/openid-configuration

You can visit this URL directly to confirm all endpoints, but Flask-pyoidc can auto-discover these for you.

Step 2: Configure Flask-pyoidc

Here's a complete, working example that maps App ID's parameters to Flask-pyoidc. I'll use auto-discovery (the recommended approach) since it's less error-prone.

First, install dependencies:

pip install flask flask-pyoidc

Then your Flask app code:

from flask import Flask
from flask_pyoidc import OIDCAuthentication
from flask_pyoidc.provider_configuration import ProviderConfiguration, ClientMetadata

app = Flask(__name__)

# Replace these with your actual App ID values
APPID_REGION = "us-south"
APPID_TENANT_ID = "your-tenant-id-12345"
CLIENT_ID = "your-client-id-abcde"
CLIENT_SECRET = "your-client-secret-xyz"
REDIRECT_URI = "https://your-flask-app.com/callback"  # Match what's in App ID console

# Initialize App ID provider config (auto-discovers endpoints via issuer URL)
appid_provider_config = ProviderConfiguration(
    issuer=f"https://{APPID_REGION}.appid.cloud.ibm.com/oauth/v4/{APPID_TENANT_ID}",
    # Optional: Specify scopes you need (e.g., openid, profile, email)
    scope=["openid", "profile", "email"]
)

# Configure your app's client metadata
client_metadata = ClientMetadata(
    client_id=CLIENT_ID,
    client_secret=CLIENT_SECRET,
    redirect_uris=[REDIRECT_URI]
)

# Set up OIDC authentication
auth = OIDCAuthentication(
    provider_configs={"default": appid_provider_config},
    client_metadata={"default": client_metadata}
)
auth.init_app(app)

# Protected route (requires authentication)
@app.route("/protected")
@auth.oidc_auth("default")
def protected():
    # Access user claims from App ID
    user_name = auth.user_getfield("name")
    user_email = auth.user_getfield("email")
    return f"Welcome {user_name}! Your email is {user_email}. Full user info: {auth.user_getinfo()}"

# Callback route (matches REDIRECT_URI)
@app.route("/callback")
@auth.oidc_callback("default")
def callback():
    return "Login successful! <a href='/protected'>Go to protected page</a>"

if __name__ == "__main__":
    # Use adhoc SSL for testing only; use a valid certificate in production
    app.run(ssl_context="adhoc", debug=True)

Key Parameter Mappings (If You Prefer Manual Configuration)

If you want to define endpoints manually instead of using auto-discovery, here's how App ID's endpoints map to Flask-pyoidc's provider_config:

  • issuer: https://<REGION>.appid.cloud.ibm.com/oauth/v4/<TENANT_ID>
  • authorization_endpoint: https://<REGION>.appid.cloud.ibm.com/oauth/v4/<TENANT_ID>/authorization
  • token_endpoint: https://<REGION>.appid.cloud.ibm.com/oauth/v4/<TENANT_ID>/token
  • userinfo_endpoint: https://<REGION>.appid.cloud.ibm.com/oauth/v4/<TENANT_ID>/userinfo
  • jwks_uri: https://<REGION>.appid.cloud.ibm.com/oauth/v4/<TENANT_ID>/publickeys (used to verify JWT signatures)

Critical Notes to Avoid Issues

  1. Redirect URI Match: The REDIRECT_URI in your code must exactly match the one you added in the App ID console (including HTTP/HTTPS and trailing slashes if present).
  2. SSL Requirement: App ID requires HTTPS for callback URLs in production. For local testing, use ssl_context='adhoc' (as in the example) or a tool like ngrok to expose your local app over HTTPS.
  3. Scopes: Make sure the scopes you request are enabled in your App ID instance (e.g., if you need email, ensure the "email" scope is allowed in the App ID "Authentication Settings").
  4. Token Validation: App ID uses RS256 for JWT signing, and Flask-pyoidc will automatically fetch the public keys from the jwks_uri to validate tokens—no extra work needed.

内容的提问来源于stack exchange,提问作者data_henrik

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 03:29:14