Single Sign-On
By the end of this page nobody at home has to remember a SkyView-only password — they get in with one click using the account on your Synology NAS, their work account or their Google account.
Before you start
Whatever they check, SkyView does not check again
1. Start with the redirect URI
When you create the application at your identity provider, it will always ask for a "redirect URI" (some consoles call it a callback URL or a reply URL). SkyView's looks like this:
https://<the address you use to open SkyView>/api/auth/oidc/callbackThe top of SkyView's settings page has already worked out the complete line from the address you are browsing right now, with a copy button next to it — copying that one is the safest thing to do.
- Use the address you actually browse to — not an address inside the container, and not
127.0.0.1. - It has to match character for character —
httpsversushttp, the port number, upper and lower case: one character out and it will not go through. - Two ways in means two entries — if you use a LAN address at home and a public domain when you are out, register both at the provider (nearly all of them accept more than one).
2. What to fill in on the SkyView side
| Field | What it does |
|---|---|
| Enable single sign-on | The master switch. Turn it off and the button disappears from the sign-in page; accounts that are already linked stay linked |
| Button name | The name shown on the button, such as "Home NAS account" or "Work account". Leave it empty and it shows SSO |
| Provider address | Paste the address your provider gives you as is. A trailing /.well-known/openid-configuration or slash is fine; SkyView trims it. Must be https |
| Client ID | You get this after creating the application at your provider |
| Client secret | Same place. It is only ever used between the SkyView server and the provider's, and never reaches a browser or a phone |
| Create an account on first sign-in | On: somebody SkyView has never seen gets a SkyView account the first time they sign in. Off: they have to be linked by hand first, and unlinked sign-ins are refused |
| Role for new accounts | Keep this at "Viewer (read-only)". Promote the people who need admin rights afterwards, one at a time, under Users |
"Advanced" holds two more, and the defaults work with nearly every provider: leave "Requested scopes" as it is, and "Username comes from" decides which of the provider's fields becomes the SkyView username — if that field is missing or unusable, SkyView generates a name instead.
Do not flip the master switch first
The ones we have been all the way through
3. Synology SSO Server
The easiest route for NAS owners: nothing extra to install — a package DSM already offers can act as the identity provider, so the accounts on the NAS sign in to SkyView directly.
- 1
Install the package and start the service
What to do: install SSO Server from Package Center, open it, and tick OIDC under Service (that is the common single sign-on standard; every console calls it by that name).
- 2
Add an application
What to do: Application → Add, set the type to OIDC, name it whatever you like ("SkyView", say), and put the redirect URI from section 1 into Redirect URI.
- 3
Copy two values back to SkyView
What to do: after saving, the list shows an Application ID and an Application Secret — those go into SkyView's "Client ID" and "Client secret".
- 4
Fill in the provider address
What to do: enter
https://<the address you use for DSM>/webman/sso, for examplehttps://nas.example.com:5001/webman/sso.
That DSM address has to be https with a valid certificate
Synology does not offer a separate username field, so SkyView uses the DSM login name as the SkyView username (whatever they are called on DSM, they are called here) and takes the display name from the email address. Leave "Username comes from" at its default.
4. Authentik
- 1
Create a provider
Where: Applications → Providers → Create in the left-hand menu, then pick OAuth2/OpenID Provider.
- 2
Fill in the parts that matter
What to do: pick the authorization flow you already have (with or without a consent screen, either is fine); set Client type to Confidential; put the redirect URI from section 1 into Redirect URIs (one per line if you have several); pick any certificate as the Signing Key.
- 3
Copy the credentials
What to do: after saving, copy Client ID and Client Secret from the provider's detail page into SkyView.
- 4
Create the application and set who can use it
What to do: Applications → Create an application bound to the provider you just made, and set who is allowed to use it while you are there.
- 5
Fill in the provider address
What to do: the OpenID Configuration Issuer on the provider's detail page is the one, something like
https://auth.example.com/application/o/skyview/. Paste the whole thing into SkyView's "Provider address". The trailing slash makes no difference.
5. Microsoft Entra ID (formerly Azure AD)
- 1
Register the application
Where: the Azure portal → Microsoft Entra ID → App registrations → New registration. Under Redirect URI, choose the Web platform and enter the redirect URI from section 1.
- 2
Collect two IDs
What to do: on the Overview page after registering, copy the Application (client) ID (→ SkyView's "Client ID") and the Directory (tenant) ID (you need it for the address in a moment).
- 3
Create a client secret
What to do: Certificates & secrets → New client secret, and copy the Value column immediately — leave the page and it is gone for good. Paste it into SkyView's "Client secret".
- 4
Fill in the provider address
What to do: enter
https://login.microsoftonline.com/<tenant ID>/v2.0.
The username Entra hands over is usually a full email address; SkyView takes the part before the @ and adds a number if that name is already taken. Leave API permissions at the defaults.
6. Google
Google will not accept a LAN address
- 1
Create the credentials
Where: Google Cloud Console → APIs & Services → Credentials → Create credentials → OAuth client ID, with the type set to Web application.
- 2
Enter the redirect URI
What to do: put the redirect URI from section 1 under Authorized redirect URIs, then create it and collect the client ID and client secret.
- 3
Fill in the provider address
What to do: enter
https://accounts.google.com. - 4
Adjust where the username comes from
What to do: Google has no username field, so set "Username comes from" to
email, or just leave the default and let SkyView generate one.
Do not let the whole world open an account on your SkyView
7. Keycloak
- 1
Create a client
Where: pick your realm → Clients → Create client, set Client type to OpenID Connect, and choose a Client ID of your own (
skyview, for instance). - 2
Make it a confidential client
What to do: on the next step turn on Client authentication, and tick Standard flow under Authentication flow.
- 3
Enter the redirect URI
What to do: put the redirect URI from section 1 into Valid redirect URIs.
- 4
Copy the secret and fill in the address
What to do: once it is created, copy Client secret from the Credentials tab; the provider address is
https://kc.example.com/realms/<realm name>.
Keycloak provides a username field out of the box, so leave "Username comes from" at its default.
8. What happens the first time somebody signs in with it
- 1
Off to the provider
What to do: click "Sign in with …" on the SkyView sign-in page, get sent to the provider, sign in the way you do there (including its own second step), and get sent back to SkyView automatically.
- 2
SkyView looks for a matching account
What to do: nothing at all — SkyView looks you up by the unique user identifier the provider sends. If it finds a link, that is you, and you are in.
- 3
Two ways it can go when there is no match
With account creation on: a new SkyView account is created there and then, with the role from the settings, and the external account is linked to it. With account creation off: it says this account is not linked to a SkyView user yet — either link it by hand as in the next section, or ask an admin to turn account creation on.
An account created this way has no local password
9. Linking an external account to an existing SkyView account
This is for "I already have a SkyView admin account and I want to sign in to it with my NAS account from now on".
- 1
Sign in to SkyView normally first
What to do: username and password, as usual.
- 2
Find the linking card
Where: Settings → My account → Sign-in security → "Linked accounts".
- 3
Click "Link … account"
What to do: you are sent to the provider to sign in once, and you come back finished. How you know it worked: the account is listed in the card, and from then on that button on the sign-in page takes you straight into this SkyView account.
One SkyView account can be linked to several provider accounts; the other way round, a provider account links to exactly one SkyView account — otherwise "who does this sign me in as" would have no definite answer. Unlinking is on the same card.
An account with no password cannot be unlinked
10. The phone apps
Android and iOS both support it: fill in the server address on the sign-in screen (the dot beside it turns green) and the button appears by itself. Tapping it opens the system browser to finish signing in, then returns to the app automatically.
- The phone's browser has to reach the same SkyView address — when you are out of the house, that means the server address field needs your public address.
- "Remember password" does not apply — that option remembers a local password, and these accounts do not have one. To save the typing, stay signed in at the provider instead and the browser will remember you.
11. Common questions
- It says the redirect URI does not match — the address registered at the provider is not the one SkyView actually sent. Open the line at the top of SkyView's settings page and compare it with the provider's console character by character: scheme, port, trailing slash, upper and lower case. A LAN entrance and a public one each need their own entry.
- It says the address does not match the identifier the service returned — the "Provider address" is not the provider's real issuer (usually copied from the wrong page). Go back to the application details at your provider and copy the "Issuer / OpenID Configuration" value again. A trailing
/.well-known/openid-configurationor slash makes no difference. - It comes back saying the sign-in did not complete — two common causes. One is the clock on the machine running SkyView: more than about two minutes away from the provider's and it gets refused, which is easy to hit on a NAS with automatic time sync switched off. The other is a wrong client secret — generate a new one, paste it in and save; an empty field means "leave it as it is", so nothing changes unless you really do paste the new value.
- How soon do changes take effect — immediately. Change the provider address and SkyView drops what it had cached about the provider, so the very next click on the button goes to the new address.
- If I turn single sign-on off, do the accounts it created stay — yes, and so do the links; the button just stops appearing on the sign-in page. To clear them out for good, delete the accounts under Users.
- Can I let only certain people use it — yes, but you manage that at the provider (Authentik policies, Google's test users list, Synology user groups). The coarse switch on the SkyView side is "Create an account on first sign-in": turn it off and only the people you linked by hand can get in.
Related guides
- Users & Permissions — giving newcomers their camera access
- Two-Step Verification — SkyView's own code; you only need one of the two
- Remote Access — setting up a domain and a certificate
Was this page helpful?