# Third Party OIDC Identity Provider: How to set up

**URL:** <https://forum.solidproject.org/t/third-party-oidc-identity-provider-how-to-set-up/5249>\
**Category:** General Discussion\
**Created:** [May 2, 2022, 3:47pm UTC](https://forum.solidproject.org/t/third-party-oidc-identity-provider-how-to-set-up/5249 "2022-05-02T15:47:41Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![skymage23](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.solidproject.org/skymage23/32/3232_2.png) [@skymage23](https://forum.solidproject.org/u/skymage23)\
**Post date:** [May 2, 2022, 3:47pm UTC](https://forum.solidproject.org/t/third-party-oidc-identity-provider-how-to-set-up/5249/1 "2022-05-02T15:47:41Z")

</div>

I would like to configure the Solid Community Server to use my own OIDC Identity Provider (Red Hat Single Sign On). How would I go about setting that up in the config files?

---

<div class="post-metadata">

**Author:** ![zwifi](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.solidproject.org/zwifi/32/1525_2.png) [@zwifi](https://forum.solidproject.org/u/zwifi)\
**Post date:** [May 10, 2022, 2:00pm UTC](https://forum.solidproject.org/t/third-party-oidc-identity-provider-how-to-set-up/5249/2 "2022-05-10T14:00:03Z")

</div>

Note that a “regular” OIDC provider will not be usable directly to authenticate for Solid, as the [Solid-OIDC specification](https://solidproject.org/TR/oidc) is an extension on top of OpenID Connect. In particular, the resulting ID token includes a new mandatory claim, `webid`, which will be missing from a stock Red Hat SSO I suspect.

You’ll probably want to implement a broker pattern, where your code acts as an intermediary between the Solid client and the non-Solid OIDC Provider, adding the missing pieces to the ID token and potentially adding support for Solid-OIDC Client Identifiers. In this type of setup, the client only talks to the identity broker, and the broker acts like a static app registered to the underlying OIDC provider.

All the ID provider related documentation in the Community Server is available at [CommunitySolidServer/identity-provider.md at main · CommunitySolidServer/CommunitySolidServer · GitHub](https://github.com/CommunitySolidServer/CommunitySolidServer/blob/main/documentation/identity-provider.md). Once you have a functioning broker, you should be able to swap out the `node-oidc-provider` extension used by CSS for your own code.

Does that answer your question?
