[Yandex Cloud documentation](../../../../index.md) > [Yandex Identity Hub](../../../index.md) > [Tutorials](../../index.md) > [Setting up single sign-on (SSO) for apps](../index.md) > LibreChat > OpenID Connect

# Creating an OIDC application in Yandex Identity Hub for integration with LibreChat

[LibreChat](https://www.librechat.ai/) is a free open-source platform that provides an easy way to work with large language models, AI agents, and MCP servers and can be deployed in your own infrastructure. LibreChat supports [OpenID Connect](https://en.wikipedia.org/wiki/OpenID#OpenID_Connect_(OIDC)) (OIDC) authentication to provide secure SSO for your organization's users.

For your [organization's](../../../concepts/organization.md) users to be able to authenticate to LibreChat via OpenID Connect SSO, create an [OIDC app](../../../concepts/applications/oidc.md) in Yandex Identity Hub and configure it both in Yandex Identity Hub and LibreChat.

OIDC apps can be managed by users with the `organization-manager.oauthApplications.admin` [role](../../../security/index.md#organization-manager-oauthApplications-admin) or higher.

To provide your organization's users with access to LibreChat:

1. [Create an app](#create-app).
1. [Set up the integration](#setup-integration).
1. [Add users](#add-users).
1. [Make sure the application works correctly](#validate).

## Create an app {#create-app}

{% list tabs group=instructions %}

- Cloud Center UI {#cloud-center}

    1. Log in to [Yandex Identity Hub](https://center.yandex.cloud/organization).
    1. In the left-hand panel, select ![shapes-4](../../../../_assets/console-icons/shapes-4.svg) **Apps**.
    1. In the top-right corner, click ![Circles3Plus](../../../../_assets/console-icons/circles-3-plus.svg) **Create application** and in the window that opens:
        1. Select the **OIDC (OpenID Connect)** single sign-on method.
        1. In the **Application type** field, select [Web Application](*web_app_type).
           
           [*web_app_type]: OIDC apps of the `Web Application` type are optimized for user authentication to external web apps with a server end (backend), where the application secret can be safely stored. For more information about OIDC application types, see [Types of OIDC apps in Yandex Identity Hub](../../../concepts/applications/oidc.md#oidc-application-types).
        1. In the **Name** field, specify a name for your new app: `librechat-oidc-app`.
        1. In the **Folder** field, select the folder where you want to create an OAuth client for your app.
        1. Optionally, add a description and [labels](../../../../resource-manager/concepts/labels.md) for the app.
        1. Click **Create application**.

{% endlist %}

## Set up the integration {#setup-integration}

To configure LibreChat integration with the OIDC app you created in Yandex Identity Hub, complete the configuration both on the Yandex Identity Hub side and in LibreChat.

### Get the application's credentials and create the application's secret {#get-credentials-secret}

{% list tabs group=instructions %}

- Cloud Center UI {#cloud-center}

    1. Log in to [Yandex Identity Hub](https://center.yandex.cloud/organization).
    1. In the left-hand panel, navigate to ![shapes-4](../../../../_assets/console-icons/shapes-4.svg) **Apps** and select `librechat-oidc-app`.
    1. On the **Overview** tab, under **Identity provider (IdP) configuration**, copy the **ClientID** field value.
    1. Create an app secret (only available for applications of the `Web Application` [type](../../../concepts/applications/oidc.md#oidc-application-types)).
       
       To do this, under **App secrets**, click **Add secret**, and in the window that opens:
       
       1. Optionally, add a description for the new secret.
       1. Click **Create**.
       
           The window will display the generated [application secret](../../../concepts/applications/oidc.md#oidc-secret). Save this value.
       
           {% note warning %}
       
           If you refresh or close the application information page, you will not be able to view the secret again.
       
           {% endnote %}
       
       If you closed or refreshed the page before saving the secret, click **Add secret** to create a new one.
       
       To delete a secret, in the list of secrets on the OIDC app page, click ![ellipsis](../../../../_assets/console-icons/ellipsis.svg) in the secret row and select ![trash-bin](../../../../_assets/console-icons/trash-bin.svg) **Delete**.

{% endlist %}

### Configure advanced OIDC app settings in Yandex Identity Hub {#setup-redirect}

{% list tabs group=instructions %}

- Cloud Center UI {#cloud-center}

    1. Log in to [Yandex Identity Hub](https://center.yandex.cloud/organization).
    1. In the left-hand panel, navigate to ![shapes-4](../../../../_assets/console-icons/shapes-4.svg) **Apps** and select `librechat-oidc-app`.
    1. At the top right, click ![pencil](../../../../_assets/console-icons/pencil.svg) **Edit** and in the window that opens:

        1. Set the **Redirect URI** field to `https://<server_address>/oauth/openid/callback`, where `<server_address>` is the public IP address or domain name of your LibreChat instance.

            {% note info %}

            In the Yandex Identity Hub OIDC app settings, the `Redirect URI` value only supports the `https://` scheme, so your LibreChat instance must be accessible over `https`.

            {% endnote %}

        1. Under **Scopes**, enable **groups (user's groups in the organization)**.
        1. Click **Save**.

{% endlist %}

### Set up OIDC authentication in LibreChat {#setup-sp}

1. On the host running your LibreChat instance, set the following environment variables in the instance runtime environment to configure LibreChat integration with the OIDC application:

    * Variables defining the main integration settings:

        Variable name | Value
        --- | ---
        `OPENID_CLIENT_ID` | **ClientID** field value obtained [earlier](#get-credentials-secret) from the Yandex Cloud OIDC app settings
        `OPENID_CLIENT_SECRET` | OIDC app secret generated [earlier](#get-credentials-secret)
        `OPENID_ISSUER` | `"https://auth.yandex.cloud/"`
        `OPENID_SESSION_SECRET` | Additional secret used to secure sessions.</br></br>Generate a strong secret of at least 32 characters.
        `OPENID_SCOPE` | `"openid profile email groups"`
        `OPENID_CALLBACK_URL` | `"/oauth/openid/callback"`
        `OPENID_USERNAME_CLAIM` | `"preferred_username"`
        `OPENID_NAME_CLAIM` | `"name"`
        `OPENID_EMAIL_CLAIM` | `"email"`
        `OPENID_USE_PKCE` | `true`
        `OPENID_BUTTON_LABEL` | `"Login with Yandex Identity Hub"`
        `OPENID_AUTO_REDIRECT` | `false`
    * Variables defining advanced settings for user group synchronization:

        Variable name | Value
        --- | ---
        `OPENID_ROLE_SYNC_ENABLED` | `true`
        `OPENID_ROLE_SYNC_API_ENABLED` | `false`
        `OPENID_ROLE_SYNC_SOURCE` | `"id"`
        `OPENID_ROLE_SYNC_CLAIM` | `"groups"`
        `OPENID_ROLE_SYNC_ROLE_PRIORITY` | List of group names in Yandex Identity Hub to synchronize with.</br></br>Here is an example: `"librechat-admins,librechat-users"`.
        `OPENID_ROLE_SYNC_FALLBACK_ROLE` | Default user group.</br></br>Here is an example: `"librechat-users"`.
1. Restart your LibreChat instance in the runtime environment with the specified environment variables.

## Add users {#add-users}

To enable users to authenticate in LibreChat:

1. In Yandex Identity Hub, [create](../../../operations/create-group.md) a [user group](../../../concepts/groups.md) under one of the names specified [earlier](#setup-sp) in the `OPENID_ROLE_SYNC_ROLE_PRIORITY` environment variable, e.g., `librechat-users`.
1. [Add](../../../operations/add-member-group.md) a user to the `librechat-users` group.
1. Add the `librechat-users` group to the Yandex Identity Hub OIDC app:

    {% note info %}
    
    Users and groups added to an OIDC application can be managed by any user with the `organization-manager.oidcApplications.userAdmin` [role](../../../security/index.md#organization-manager-oidcApplications-userAdmin) or higher.
    
    {% endnote %}

    {% list tabs group=instructions %}

    - Cloud Center UI {#cloud-center}

        1. Log in to [Yandex Identity Hub](https://center.yandex.cloud/organization).
        1. In the left-hand panel, navigate to ![shapes-4](../../../../_assets/console-icons/shapes-4.svg) **Apps** and select `librechat-oidc-app`.
        1. Navigate to the **Users and groups** tab.
        1. Click ![person-plus](../../../../_assets/console-icons/person-plus.svg) **Add users**.
        1. In the window that opens, navigate to the **Groups** tab and select `librechat-users`.
        1. Click **Add**.

    {% endlist %}

{% note tip %}

If you want to fine-tune user authentication in your applications, including authentication only from specific IP addresses, use [authentication policies](*authentication_policies).

{% endnote %}

[*authentication_policies]: Authentication policies are a Yandex Identity Hub tool that allows you to flexibly configure access to applications by denying or allowing authentication for specific users in specific applications and/or from specific IP addresses. For more information, see [Authentication policies in Yandex Identity Hub](../../../concepts/authentication-policy.md).

## Make sure your application works correctly {#validate}

To ensure that your OIDC application and integration with LibreChat are working correctly, log in to LibreChat as one of the users added to the `librechat-users` group. Follow these steps:

1. In your browser, open the LibreChat instance login page.
1. Select login via Yandex Identity Hub.
1. Authenticate in Yandex Cloud as a user of your organization.
1. After authenticating successfully, make sure you are logged in to LibreChat and your authorized user belongs to the same group, `librechat-users`, in both LibreChat and Yandex Identity Hub.