[{"data":1,"prerenderedAt":1738},["ShallowReactive",2],{"navigation_docs_en":3,"-en-serveex-security-pocket-id-":377,"-en-serveex-security-pocket-id--surround":1733},[4,16,94,262,271,332],{"title":5,"icon":6,"path":7,"stem":8,"children":9,"page":15},"About","i-noto-star","\u002Fen\u002Fabout","en\u002F1.about",[10],{"title":11,"path":12,"stem":13,"icon":14},"Welcome","\u002Fen\u002Fabout\u002Fwelcome","en\u002F1.about\u002F1.welcome","i-lucide-home",false,{"title":17,"icon":18,"path":19,"stem":20,"children":21,"page":15},"General","i-noto-open-book","\u002Fen\u002Fgeneral","en\u002F2.general",[22,26,44,58,76],{"title":17,"path":23,"stem":24,"icon":25},"\u002Fen\u002Fgeneral\u002Fsummary","en\u002F2.general\u002F1.summary","i-lucide-bookmark",{"title":27,"icon":28,"path":29,"stem":30,"children":31,"page":15},"Networking","i-lucide-network","\u002Fen\u002Fgeneral\u002Fnetworking","en\u002F2.general\u002F2.networking",[32,36,40],{"title":33,"path":34,"stem":35},"NAT & DHCP","\u002Fen\u002Fgeneral\u002Fnetworking\u002Fnat","en\u002F2.general\u002F2.networking\u002F1.nat",{"title":37,"path":38,"stem":39},"DNS Zone","\u002Fen\u002Fgeneral\u002Fnetworking\u002Fdns","en\u002F2.general\u002F2.networking\u002F2.dns",{"title":41,"path":42,"stem":43},"Samba","\u002Fen\u002Fgeneral\u002Fnetworking\u002Fsamba","en\u002F2.general\u002F2.networking\u002F3.samba",{"title":45,"icon":46,"path":47,"stem":48,"children":49,"page":15},"Storage","i-lucide-hard-drive","\u002Fen\u002Fgeneral\u002Fstorage","en\u002F2.general\u002F3.storage",[50,54],{"title":51,"path":52,"stem":53},"RAID","\u002Fen\u002Fgeneral\u002Fstorage\u002Fraid","en\u002F2.general\u002F3.storage\u002F1.raid",{"title":55,"path":56,"stem":57},"ZFS","\u002Fen\u002Fgeneral\u002Fstorage\u002Fzfs","en\u002F2.general\u002F3.storage\u002F2.zfs",{"title":59,"icon":60,"path":61,"stem":62,"children":63,"page":15},"Hardware","i-lucide-server","\u002Fen\u002Fgeneral\u002Fhardware","en\u002F2.general\u002F4.hardware",[64,68,72],{"title":65,"path":66,"stem":67},"The Basics","\u002Fen\u002Fgeneral\u002Fhardware\u002Fbasics","en\u002F2.general\u002F4.hardware\u002F1.basics",{"title":69,"path":70,"stem":71},"Network","\u002Fen\u002Fgeneral\u002Fhardware\u002Fnetwork","en\u002F2.general\u002F4.hardware\u002F2.network",{"title":73,"path":74,"stem":75},"The ProloNAS","\u002Fen\u002Fgeneral\u002Fhardware\u002Fprolonas","en\u002F2.general\u002F4.hardware\u002F3.prolonas",{"title":77,"icon":78,"path":79,"stem":80,"children":81,"page":15},"Linux tips for dummies","i-lucide-terminal","\u002Fen\u002Fgeneral\u002Flinux","en\u002F2.general\u002F5.linux",[82,86,90],{"title":83,"path":84,"stem":85},"Command line basics","\u002Fen\u002Fgeneral\u002Flinux\u002Fcli-basics","en\u002F2.general\u002F5.linux\u002F1.cli-basics",{"title":87,"path":88,"stem":89},"Folders and partitions","\u002Fen\u002Fgeneral\u002Flinux\u002Ffilesystem","en\u002F2.general\u002F5.linux\u002F2.filesystem",{"title":91,"path":92,"stem":93},"Handy CLI tools","\u002Fen\u002Fgeneral\u002Flinux\u002Fhandy-tools","en\u002F2.general\u002F5.linux\u002F3.handy-tools",{"title":95,"icon":96,"path":97,"stem":98,"children":99,"page":15},"Serveex","i-noto-microscope","\u002Fen\u002Fserveex","en\u002F3.serveex",[100,104,126,144,170,188,202,216,234,248],{"title":101,"path":102,"stem":103,"icon":25},"Introduction","\u002Fen\u002Fserveex\u002Fintroduction","en\u002F3.serveex\u002F1.introduction",{"title":105,"icon":106,"path":107,"stem":108,"children":109,"page":15},"Server core","i-lucide-server-cog","\u002Fen\u002Fserveex\u002Fcore","en\u002F3.serveex\u002F2.core",[110,114,118,122],{"title":111,"path":112,"stem":113},"Debian 13","\u002Fen\u002Fserveex\u002Fcore\u002Finstallation","en\u002F3.serveex\u002F2.core\u002F1.installation",{"title":115,"path":116,"stem":117},"Docker","\u002Fen\u002Fserveex\u002Fcore\u002Fdocker","en\u002F3.serveex\u002F2.core\u002F2.docker",{"title":119,"path":120,"stem":121},"Wireguard","\u002Fen\u002Fserveex\u002Fcore\u002Fwireguard","en\u002F3.serveex\u002F2.core\u002F3.wireguard",{"title":123,"path":124,"stem":125},"SWAG","\u002Fen\u002Fserveex\u002Fcore\u002Fswag","en\u002F3.serveex\u002F2.core\u002F4.swag",{"title":127,"icon":128,"path":129,"stem":130,"children":131,"page":15},"Security","i-lucide-shield","\u002Fen\u002Fserveex\u002Fsecurity","en\u002F3.serveex\u002F3.security",[132,136,140],{"title":133,"path":134,"stem":135},"Cloudflare Zero Trust","\u002Fen\u002Fserveex\u002Fsecurity\u002Fcloudflare","en\u002F3.serveex\u002F3.security\u002F2.cloudflare",{"title":137,"path":138,"stem":139},"TinyAuth","\u002Fen\u002Fserveex\u002Fsecurity\u002Ftinyauth","en\u002F3.serveex\u002F3.security\u002F3.tinyauth",{"title":141,"path":142,"stem":143},"Pocket ID","\u002Fen\u002Fserveex\u002Fsecurity\u002Fpocket-id","en\u002F3.serveex\u002F3.security\u002F4.pocket-id",{"title":145,"icon":146,"path":147,"stem":148,"children":149,"page":15},"Monitoring","i-lucide-chart-no-axes-column","\u002Fen\u002Fserveex\u002Fmonitoring","en\u002F3.serveex\u002F4.monitoring",[150,154,158,162,166],{"title":151,"path":152,"stem":153},"Uptime-Kuma","\u002Fen\u002Fserveex\u002Fmonitoring\u002Fuptime-kuma","en\u002F3.serveex\u002F4.monitoring\u002F1.uptime-kuma",{"title":155,"path":156,"stem":157},"Dozzle","\u002Fen\u002Fserveex\u002Fmonitoring\u002Fdozzle","en\u002F3.serveex\u002F4.monitoring\u002F2.dozzle",{"title":159,"path":160,"stem":161},"Speedtest Tracker","\u002Fen\u002Fserveex\u002Fmonitoring\u002Fspeedtest-tracker","en\u002F3.serveex\u002F4.monitoring\u002F3.speedtest-tracker",{"title":163,"path":164,"stem":165},"Beszel","\u002Fen\u002Fserveex\u002Fmonitoring\u002Fbeszel","en\u002F3.serveex\u002F4.monitoring\u002F4.beszel",{"title":167,"path":168,"stem":169},"UpSnap","\u002Fen\u002Fserveex\u002Fmonitoring\u002Fupsnap","en\u002F3.serveex\u002F4.monitoring\u002F5.upsnap",{"title":171,"icon":172,"path":173,"stem":174,"children":175,"page":15},"Media & Seedbox","i-lucide-list-video","\u002Fen\u002Fserveex\u002Fmedia","en\u002F3.serveex\u002F5.media",[176,180,184],{"title":177,"path":178,"stem":179},"Jellyfin","\u002Fen\u002Fserveex\u002Fmedia\u002Fjellyfin","en\u002F3.serveex\u002F5.media\u002F1.jellyfin",{"title":181,"path":182,"stem":183},"Qbittorrent","\u002Fen\u002Fserveex\u002Fmedia\u002Fqbittorrent","en\u002F3.serveex\u002F5.media\u002F2.qbittorrent",{"title":185,"path":186,"stem":187},"Automation","\u002Fen\u002Fserveex\u002Fmedia\u002Fservarr","en\u002F3.serveex\u002F5.media\u002F3.servarr",{"title":189,"icon":190,"path":191,"stem":192,"children":193,"page":15},"Cloud Drive & Photos","i-lucide-cloud-upload","\u002Fen\u002Fserveex\u002Fcloud","en\u002F3.serveex\u002F6.cloud",[194,198],{"title":195,"path":196,"stem":197},"Immich","\u002Fen\u002Fserveex\u002Fcloud\u002Fimmich","en\u002F3.serveex\u002F6.cloud\u002F1.immich",{"title":199,"path":200,"stem":201},"Nextcloud","\u002Fen\u002Fserveex\u002Fcloud\u002Fnextcloud","en\u002F3.serveex\u002F6.cloud\u002F2.nextcloud",{"title":203,"icon":204,"path":205,"stem":206,"children":207,"page":15},"File & share","i-lucide-folder-tree","\u002Fen\u002Fserveex\u002Ffiles","en\u002F3.serveex\u002F7.files",[208,212],{"title":209,"path":210,"stem":211},"File Browser Quantum","\u002Fen\u002Fserveex\u002Ffiles\u002Ffile-browser-quantum","en\u002F3.serveex\u002F7.files\u002F1.file-browser-quantum",{"title":213,"path":214,"stem":215},"Pingvin","\u002Fen\u002Fserveex\u002Ffiles\u002Fpingvin","en\u002F3.serveex\u002F7.files\u002F2.pingvin",{"title":217,"icon":218,"path":219,"stem":220,"children":221,"page":15},"Developpement","i-lucide-code-xml","\u002Fen\u002Fserveex\u002Fdevelopment","en\u002F3.serveex\u002F8.development",[222,226,230],{"title":223,"path":224,"stem":225},"Code-Server","\u002Fen\u002Fserveex\u002Fdevelopment\u002Fcode-server","en\u002F3.serveex\u002F8.development\u002F1.code-server",{"title":227,"path":228,"stem":229},"Forgejo","\u002Fen\u002Fserveex\u002Fdevelopment\u002Fforgejo","en\u002F3.serveex\u002F8.development\u002F2.forgejo",{"title":231,"path":232,"stem":233},"IT Tools","\u002Fen\u002Fserveex\u002Fdevelopment\u002Fit-tools","en\u002F3.serveex\u002F8.development\u002F3.it-tools",{"title":235,"icon":236,"path":237,"stem":238,"children":239,"page":15},"Useful Apps","i-lucide-award","\u002Fen\u002Fserveex\u002Fapps","en\u002F3.serveex\u002F9.apps",[240,244],{"title":241,"path":242,"stem":243},"Adguard Home","\u002Fen\u002Fserveex\u002Fapps\u002Fadguard","en\u002F3.serveex\u002F9.apps\u002F1.adguard",{"title":245,"path":246,"stem":247},"Vaultwarden","\u002Fen\u002Fserveex\u002Fapps\u002Fvaultwarden","en\u002F3.serveex\u002F9.apps\u002F2.vaultwarden",{"title":249,"icon":250,"path":251,"stem":252,"children":253,"page":15},"Advanced","i-lucide-flask-conical","\u002Fen\u002Fserveex\u002Fadvanced","en\u002F3.serveex\u002F91.advanced",[254,258],{"title":255,"path":256,"stem":257},"Authentik","\u002Fen\u002Fserveex\u002Fadvanced\u002Fauthentik","en\u002F3.serveex\u002F91.advanced\u002F1.authentik",{"title":259,"path":260,"stem":261},"Arcane","\u002Fen\u002Fserveex\u002Fadvanced\u002Farcane","en\u002F3.serveex\u002F91.advanced\u002F2.arcane",{"title":263,"icon":264,"path":265,"stem":266,"children":267,"page":15},"Stockeex","i-noto-computer-disk","\u002Fen\u002Fstockeex","en\u002F4.stockeex",[268],{"title":101,"path":269,"stem":270,"icon":25},"\u002Fen\u002Fstockeex\u002Fintroduction","en\u002F4.stockeex\u002F1.introduction",{"title":272,"icon":273,"path":274,"stem":275,"children":276,"page":15},"My nonsense","i-noto-test-tube","\u002Fen\u002Fnonsense","en\u002F5.nonsense",[277,280,302],{"title":272,"path":278,"stem":279,"icon":25},"\u002Fen\u002Fnonsense\u002Fsummary","en\u002F5.nonsense\u002F1.summary",{"title":281,"icon":282,"path":283,"stem":284,"children":285,"page":15},"Python","i-lucide-file-code-2","\u002Fen\u002Fnonsense\u002Fpython","en\u002F5.nonsense\u002F2.python",[286,290,294,298],{"title":287,"path":288,"stem":289},"Nvidia Stock Bot","\u002Fen\u002Fnonsense\u002Fpython\u002Fnvidia-stock-bot","en\u002F5.nonsense\u002F2.python\u002F1.nvidia-stock-bot",{"title":291,"path":292,"stem":293},"Adguard CIDRE","\u002Fen\u002Fnonsense\u002Fpython\u002Fadguard-cidre","en\u002F5.nonsense\u002F2.python\u002F2.adguard-cidre",{"title":295,"path":296,"stem":297},"Lumeex","\u002Fen\u002Fnonsense\u002Fpython\u002Flumeex","en\u002F5.nonsense\u002F2.python\u002F3.lumeex",{"title":299,"path":300,"stem":301},"Instameex","\u002Fen\u002Fnonsense\u002Fpython\u002Finstameex","en\u002F5.nonsense\u002F2.python\u002F4.instameex",{"title":303,"icon":304,"path":305,"stem":306,"children":307,"page":15},"Bash","i-lucide-file-terminal","\u002Fen\u002Fnonsense\u002Fbash","en\u002F5.nonsense\u002F3.bash",[308,312,316,320,324,328],{"title":309,"path":310,"stem":311},"Servarr corrector","\u002Fen\u002Fnonsense\u002Fbash\u002Fservarr-duplicates","en\u002F5.nonsense\u002F3.bash\u002F1.servarr-duplicates",{"title":313,"path":314,"stem":315},"LUKS Backup","\u002Fen\u002Fnonsense\u002Fbash\u002Fluks-backup","en\u002F5.nonsense\u002F3.bash\u002F2.luks-backup",{"title":317,"path":318,"stem":319},"Socat Proxy","\u002Fen\u002Fnonsense\u002Fbash\u002Fsocat-proxy","en\u002F5.nonsense\u002F3.bash\u002F3.socat-proxy",{"title":321,"path":322,"stem":323},"HotDisk","\u002Fen\u002Fnonsense\u002Fbash\u002Fhotdisk","en\u002F5.nonsense\u002F3.bash\u002F4.hotdisk",{"title":325,"path":326,"stem":327},"Backrest Docker Stop","\u002Fen\u002Fnonsense\u002Fbash\u002Fbackrest-docker-stop","en\u002F5.nonsense\u002F3.bash\u002F5.backrest-docker-stop",{"title":329,"path":330,"stem":331},"rm Confirmation Guard","\u002Fen\u002Fnonsense\u002Fbash\u002Frm-confirmation","en\u002F5.nonsense\u002F3.bash\u002F6.rm-confirmation",{"title":333,"icon":334,"path":335,"stem":336,"children":337,"page":15},"Recycled","i-noto-recycling-symbol","\u002Fen\u002Frecycled","en\u002F6.recycled",[338,341,355],{"title":333,"path":339,"stem":340,"icon":25},"\u002Fen\u002Frecycled\u002Fsummary","en\u002F6.recycled\u002F1.summary",{"title":342,"icon":343,"path":344,"stem":345,"children":346,"page":15},"Deprecated","i-lucide-trash-2","\u002Fen\u002Frecycled\u002Fdeprecated","en\u002F6.recycled\u002F2.deprecated",[347,351],{"title":348,"path":349,"stem":350},"Wireguard 14","\u002Fen\u002Frecycled\u002Fdeprecated\u002Fwireguard-14","en\u002F6.recycled\u002F2.deprecated\u002F1.wireguard-14",{"title":352,"path":353,"stem":354},"File Browser","\u002Fen\u002Frecycled\u002Fdeprecated\u002Ffile-browser","en\u002F6.recycled\u002F2.deprecated\u002F2.file-browser",{"title":356,"icon":357,"path":358,"stem":359,"children":360,"page":15},"Alternatives","i-lucide-arrow-left-right","\u002Fen\u002Frecycled\u002Falternatives","en\u002F6.recycled\u002F3.alternatives",[361,365,369,373],{"title":362,"path":363,"stem":364},"Plex","\u002Fen\u002Frecycled\u002Falternatives\u002Fplex","en\u002F6.recycled\u002F3.alternatives\u002F1.plex",{"title":366,"path":367,"stem":368},"Qbittorrent for Plex","\u002Fen\u002Frecycled\u002Falternatives\u002Fqbittorrent-for-plex","en\u002F6.recycled\u002F3.alternatives\u002F2.qbittorrent for plex",{"title":370,"path":371,"stem":372},"Servarr for Plex","\u002Fen\u002Frecycled\u002Falternatives\u002Fservarr-for-plex","en\u002F6.recycled\u002F3.alternatives\u002F3.servarr for plex",{"title":374,"path":375,"stem":376},"Gitea","\u002Fen\u002Frecycled\u002Falternatives\u002Fgitea","en\u002F6.recycled\u002F3.alternatives\u002F4.gitea",{"id":378,"title":141,"body":379,"contributors":1725,"description":1727,"extension":1728,"hideCopyPage":15,"hideHeader":15,"hideToc":15,"links":1729,"meta":1730,"navigation":1063,"path":142,"seo":1731,"stem":143,"__hash__":1732},"docs_en\u002Fen\u002F3.serveex\u002F3.security\u002F4.pocket-id.md",{"type":380,"value":381,"toc":1697},"minimark",[382,390,405,412,419,437,442,446,917,921,927,938,945,949,952,988,1405,1409,1415,1462,1466,1471,1690,1693],[383,384],"ellipsis",{"blur":385,"left":386,"top":387,"width":388,"z-index":389},"140px","0px","10rem","40rem","60",[391,392,393,399,400,404],"p",{},[394,395,141],"a",{"href":396,"rel":397},"https:\u002F\u002Fpocket-id.org",[398],"nofollow"," is a minimalist, self-hosted OIDC (OpenID Connect) provider built entirely around passkeys: instead of managing passwords, you and your users log in to compatible apps with a ",[401,402,403],"strong",{},"passkey"," (fingerprint, face unlock, or a hardware security key). It runs as a single lightweight container with no external database to manage, and it does exactly one thing well: issuing OIDC logins.",[391,406,407],{},[408,409],"img",{"alt":410,"src":411},"pocketid","\u002Fimg\u002Fserveex\u002Fpocketid.png",[391,413,414,415,418],{},"This makes it a good fit if you just need a simple, fast SSO backend, for example to pair with ",[394,416,137],{"href":417},"\u002Fserveex\u002Fsecurity\u002Ftinyauth"," as a lightweight forward-auth setup, or to log in directly to apps that natively support OIDC.",[420,421,422,430],"ul",{},[423,424,425],"li",{},[394,426,429],{"href":427,"rel":428},"https:\u002F\u002Fpocket-id.org\u002Fdocs",[398],"Pocket ID documentation",[423,431,432],{},[394,433,436],{"href":434,"rel":435},"https:\u002F\u002Fgithub.com\u002Fpocket-id\u002Fpocket-id",[398],"Pocket ID on GitHub",[438,439,441],"h2",{"id":440},"installation","Installation",[443,444],"file-tree",{":tree":445},"{\"\u002F\":[{\"srv\":[{\"docker\":[{\"pocket-id\":[\"compose.yaml\",\".env\",\"data\u002F\"]}]}]}]}",[447,448,450,455,486,490,510,517,521,532,740,787,791,797,835,906,913],"steps",{"level":449},"3",[451,452,454],"h3",{"id":453},"create-the-data-folder","Create the data folder",[456,457,463],"pre",{"className":458,"code":459,"filename":460,"language":461,"meta":462,"style":462},"language-bash shiki shiki-themes github-dark material-theme github-dark","sudo mkdir -p \u002Fsrv\u002Fdocker\u002Fpocket-id\u002Fdata\n","Terminal","bash","",[464,465,466],"code",{"__ignoreMap":462},[467,468,471,475,479,483],"span",{"class":469,"line":470},"line",1,[467,472,474],{"class":473},"sEgDM","sudo",[467,476,478],{"class":477},"s11XM"," mkdir",[467,480,482],{"class":481},"sJWha"," -p",[467,484,485],{"class":477}," \u002Fsrv\u002Fdocker\u002Fpocket-id\u002Fdata\n",[451,487,489],{"id":488},"generate-an-encryption-key","Generate an encryption key",[456,491,493],{"className":458,"code":492,"filename":460,"language":461,"meta":462,"style":462},"openssl rand -base64 32\n",[464,494,495],{"__ignoreMap":462},[467,496,497,500,503,506],{"class":469,"line":470},[467,498,499],{"class":473},"openssl",[467,501,502],{"class":477}," rand",[467,504,505],{"class":481}," -base64",[467,507,509],{"class":508},"swwWl"," 32\n",[391,511,512,513,516],{},"Keep the output, you'll need it for the ",[464,514,515],{},".env"," file below.",[451,518,520],{"id":519},"deploy-the-stack","Deploy the stack",[391,522,523,524,527,528,531],{},"Open Dockge, click ",[464,525,526],{},"compose",", name the stack ",[464,529,530],{},"pocket-id",", and add the following config:",[456,533,538],{"className":534,"code":535,"filename":536,"language":537,"meta":462,"style":462},"language-yaml shiki shiki-themes github-dark material-theme github-dark","---\nservices:\n  pocket-id:\n    image: pocketid\u002Fpocket-id:v2\n    container_name: pocket-id\n    restart: unless-stopped\n    env_file:\n      - .env\n    volumes:\n      - \u002Fsrv\u002Fdocker\u002Fpocket-id\u002Fdata:\u002Fapp\u002Fdata\n    ports:\n      - 1411:1411\n    healthcheck:\n      test: [\"CMD\", \"curl\", \"-f\", \"http:\u002F\u002Flocalhost:1411\u002Fhealthz\"]\n      interval: 90s\n      timeout: 5s\n      retries: 3\n","compose.yaml","yaml",[464,539,540,545,556,564,576,587,598,606,615,623,631,639,647,655,707,718,729],{"__ignoreMap":462},[467,541,542],{"class":469,"line":470},[467,543,544],{"class":473},"---\n",[467,546,548,552],{"class":469,"line":547},2,[467,549,551],{"class":550},"sRuoG","services",[467,553,555],{"class":554},"s8jd1",":\n",[467,557,559,562],{"class":469,"line":558},3,[467,560,561],{"class":550},"  pocket-id",[467,563,555],{"class":554},[467,565,567,570,573],{"class":469,"line":566},4,[467,568,569],{"class":550},"    image",[467,571,572],{"class":554},":",[467,574,575],{"class":477}," pocketid\u002Fpocket-id:v2\n",[467,577,579,582,584],{"class":469,"line":578},5,[467,580,581],{"class":550},"    container_name",[467,583,572],{"class":554},[467,585,586],{"class":477}," pocket-id\n",[467,588,590,593,595],{"class":469,"line":589},6,[467,591,592],{"class":550},"    restart",[467,594,572],{"class":554},[467,596,597],{"class":477}," unless-stopped\n",[467,599,601,604],{"class":469,"line":600},7,[467,602,603],{"class":550},"    env_file",[467,605,555],{"class":554},[467,607,609,612],{"class":469,"line":608},8,[467,610,611],{"class":554},"      -",[467,613,614],{"class":477}," .env\n",[467,616,618,621],{"class":469,"line":617},9,[467,619,620],{"class":550},"    volumes",[467,622,555],{"class":554},[467,624,626,628],{"class":469,"line":625},10,[467,627,611],{"class":554},[467,629,630],{"class":477}," \u002Fsrv\u002Fdocker\u002Fpocket-id\u002Fdata:\u002Fapp\u002Fdata\n",[467,632,634,637],{"class":469,"line":633},11,[467,635,636],{"class":550},"    ports",[467,638,555],{"class":554},[467,640,642,644],{"class":469,"line":641},12,[467,643,611],{"class":554},[467,645,646],{"class":477}," 1411:1411\n",[467,648,650,653],{"class":469,"line":649},13,[467,651,652],{"class":550},"    healthcheck",[467,654,555],{"class":554},[467,656,658,661,663,666,670,673,675,678,681,684,686,688,690,693,695,697,699,702,704],{"class":469,"line":657},14,[467,659,660],{"class":550},"      test",[467,662,572],{"class":554},[467,664,665],{"class":554}," [",[467,667,669],{"class":668},"s8K8j","\"",[467,671,672],{"class":477},"CMD",[467,674,669],{"class":668},[467,676,677],{"class":554},",",[467,679,680],{"class":668}," \"",[467,682,683],{"class":477},"curl",[467,685,669],{"class":668},[467,687,677],{"class":554},[467,689,680],{"class":668},[467,691,692],{"class":477},"-f",[467,694,669],{"class":668},[467,696,677],{"class":554},[467,698,680],{"class":668},[467,700,701],{"class":477},"http:\u002F\u002Flocalhost:1411\u002Fhealthz",[467,703,669],{"class":668},[467,705,706],{"class":554},"]\n",[467,708,710,713,715],{"class":469,"line":709},15,[467,711,712],{"class":550},"      interval",[467,714,572],{"class":554},[467,716,717],{"class":477}," 90s\n",[467,719,721,724,726],{"class":469,"line":720},16,[467,722,723],{"class":550},"      timeout",[467,725,572],{"class":554},[467,727,728],{"class":477}," 5s\n",[467,730,732,735,737],{"class":469,"line":731},17,[467,733,734],{"class":550},"      retries",[467,736,572],{"class":554},[467,738,739],{"class":508}," 3\n",[741,742,743,746],"tip",{"icon":462},[391,744,745],{},"✨ Add the Watchtower label to automate updates:",[456,747,749],{"className":534,"code":748,"filename":536,"language":537,"meta":462,"style":462},"---\nservices:\n  pocket-id:\n    #...\n    labels:\n      - com.centurylinklabs.watchtower.enable=true\n",[464,750,751,755,761,767,773,780],{"__ignoreMap":462},[467,752,753],{"class":469,"line":470},[467,754,544],{"class":473},[467,756,757,759],{"class":469,"line":547},[467,758,551],{"class":550},[467,760,555],{"class":554},[467,762,763,765],{"class":469,"line":558},[467,764,561],{"class":550},[467,766,555],{"class":554},[467,768,769],{"class":469,"line":566},[467,770,772],{"class":771},"sDvJj","    #...\n",[467,774,775,778],{"class":469,"line":578},[467,776,777],{"class":550},"    labels",[467,779,555],{"class":554},[467,781,782,784],{"class":469,"line":589},[467,783,611],{"class":554},[467,785,786],{"class":477}," com.centurylinklabs.watchtower.enable=true\n",[451,788,790],{"id":789},"set-your-environment-variables","Set your environment variables",[391,792,793,794,796],{},"Fill in the ",[464,795,515],{}," file:",[456,798,802],{"className":799,"code":800,"filename":515,"language":801,"meta":462,"style":462},"language-properties shiki shiki-themes github-dark material-theme github-dark","APP_URL=https:\u002F\u002Fid.mydomain.com\nENCRYPTION_KEY=\nTRUST_PROXY=true\n","properties",[464,803,804,817,825],{"__ignoreMap":462},[467,805,806,810,813],{"class":469,"line":470},[467,807,809],{"class":808},"szyEh","APP_URL",[467,811,812],{"class":554},"=",[467,814,816],{"class":815},"slcoZ","https:\u002F\u002Fid.mydomain.com\n",[467,818,819,822],{"class":469,"line":547},[467,820,821],{"class":808},"ENCRYPTION_KEY",[467,823,824],{"class":554},"=\n",[467,826,827,830,832],{"class":469,"line":558},[467,828,829],{"class":808},"TRUST_PROXY",[467,831,812],{"class":554},[467,833,834],{"class":815},"true\n",[836,837,838,854],"table",{},[839,840,841],"thead",{},[842,843,844,848,851],"tr",{},[845,846,847],"th",{},"Variable",[845,849,850],{},"Value",[845,852,853],{},"Example",[855,856,857,874,890],"tbody",{},[842,858,859,866,869],{},[860,861,862],"td",{},[464,863,864],{"className":799,"language":801,"style":462},[467,865,809],{"class":815},[860,867,868],{},"The public URL you'll use to reach Pocket ID (see exposure below)",[860,870,871],{},[464,872,873],{},"https:\u002F\u002Fid.mydomain.com",[842,875,876,882,885],{},[860,877,878],{},[464,879,880],{"className":799,"language":801,"style":462},[467,881,821],{"class":815},[860,883,884],{},"The key generated above",[860,886,887],{},[464,888,889],{},"Q2pVEqsTNRkJSO9SkJzU3KZ2...",[842,891,892,898,901],{},[860,893,894],{},[464,895,896],{"className":799,"language":801,"style":462},[467,897,829],{"class":815},[860,899,900],{},"Required since Pocket ID sits behind Swag",[860,902,903],{},[464,904,905],{},"true",[391,907,908,909,912],{},"Deploy the stack. The local interface is available at ",[464,910,911],{},"http:\u002F\u002Fyourserverip:1411",".",[451,914,916],{"id":915},"done","Done !",[438,918,920],{"id":919},"first-login","First login",[391,922,923,924,926],{},"Pocket ID doesn't use passwords: your first account is created with a ",[401,925,403],{},", which your browser or OS will generate for you (Windows Hello, Touch ID, a phone, or a hardware key like a YubiKey).",[420,928,929,935],{},[423,930,931,932],{},"Go to ",[464,933,934],{},"http:\u002F\u002Fyourserverip:1411\u002Fsetup",[423,936,937],{},"Follow the prompts to create your admin account and register your first passkey",[939,940,941,942,944],"note",{},"Since ",[464,943,809],{}," is already set to your future public domain, passkey registration may ask you to open Pocket ID from that domain instead. Expose it first (see below) if setup doesn't complete locally.",[438,946,948],{"id":947},"exposing-pocket-id-with-swag","Exposing Pocket ID with Swag",[391,950,951],{},"Other apps need to reach Pocket ID over HTTPS to complete the OIDC login flow, so it must be exposed even if you only use it from home.",[939,953,954,955,958,959,962,963,966,967,971,972,976,977,980,981,983,984,912],{},"We assume you have the subdomain ",[464,956,957],{},"id.mydomain.com"," with a ",[464,960,961],{},"CNAME"," pointing to ",[464,964,965],{},"mydomain.com"," in your ",[394,968,970],{"href":969},"\u002Fgeneral\u002Fnetworking\u002Fdns","DNS zone",". And of course, ",[394,973,975],{"href":974},"\u002Fserveex\u002Fsecurity\u002Fcloudflare","unless you use Cloudflare Zero Trust",", your box's port ",[464,978,979],{},"443"," must be forwarded to your server's port ",[464,982,979],{}," in ",[394,985,987],{"href":986},"\u002Fgeneral\u002Fnetworking\u002Fnat","NAT rules",[447,989,990,994,997,1116,1119,1129,1133,1139,1150,1165,1168,1366,1370,1386,1390,1396,1402],{"level":449},[451,991,993],{"id":992},"add-pocket-ids-network-to-swag","Add Pocket ID's network to SWAG",[391,995,996],{},"Go to Dockge and edit SWAG's compose file by adding Pocket ID's network:",[456,998,1000],{"className":534,"code":999,"filename":536,"language":537,"meta":462,"style":462},"---\nservices:\n  swag:\n     container_name: # ...\n      # ... \n     networks:                # Attach container to custom network \n      # ...           \n      - pocket-id             # Name of the declared network\n\nnetworks:                     # Define the custom network\n  # ...\n  pocket-id:                  # Declared network name\n    name: pocket-id_default   # Actual external network name\n    external: true            # Marks it as externally defined\n",[464,1001,1002,1006,1012,1019,1029,1034,1044,1049,1059,1065,1075,1080,1089,1102],{"__ignoreMap":462},[467,1003,1004],{"class":469,"line":470},[467,1005,544],{"class":473},[467,1007,1008,1010],{"class":469,"line":547},[467,1009,551],{"class":550},[467,1011,555],{"class":554},[467,1013,1014,1017],{"class":469,"line":558},[467,1015,1016],{"class":550},"  swag",[467,1018,555],{"class":554},[467,1020,1021,1024,1026],{"class":469,"line":566},[467,1022,1023],{"class":550},"     container_name",[467,1025,572],{"class":554},[467,1027,1028],{"class":771}," # ...\n",[467,1030,1031],{"class":469,"line":578},[467,1032,1033],{"class":771},"      # ... \n",[467,1035,1036,1039,1041],{"class":469,"line":589},[467,1037,1038],{"class":550},"     networks",[467,1040,572],{"class":554},[467,1042,1043],{"class":771},"                # Attach container to custom network \n",[467,1045,1046],{"class":469,"line":600},[467,1047,1048],{"class":771},"      # ...           \n",[467,1050,1051,1053,1056],{"class":469,"line":608},[467,1052,611],{"class":554},[467,1054,1055],{"class":477}," pocket-id",[467,1057,1058],{"class":771},"             # Name of the declared network\n",[467,1060,1061],{"class":469,"line":617},[467,1062,1064],{"emptyLinePlaceholder":1063},true,"\n",[467,1066,1067,1070,1072],{"class":469,"line":625},[467,1068,1069],{"class":550},"networks",[467,1071,572],{"class":554},[467,1073,1074],{"class":771},"                     # Define the custom network\n",[467,1076,1077],{"class":469,"line":633},[467,1078,1079],{"class":771},"  # ...\n",[467,1081,1082,1084,1086],{"class":469,"line":641},[467,1083,561],{"class":550},[467,1085,572],{"class":554},[467,1087,1088],{"class":771},"                  # Declared network name\n",[467,1090,1091,1094,1096,1099],{"class":469,"line":649},[467,1092,1093],{"class":550},"    name",[467,1095,572],{"class":554},[467,1097,1098],{"class":477}," pocket-id_default",[467,1100,1101],{"class":771},"   # Actual external network name\n",[467,1103,1104,1107,1109,1113],{"class":469,"line":657},[467,1105,1106],{"class":550},"    external",[467,1108,572],{"class":554},[467,1110,1112],{"class":1111},"s08Ry"," true",[467,1114,1115],{"class":771},"            # Marks it as externally defined\n",[391,1117,1118],{},"Redeploy the stack and wait for SWAG to be fully operational.",[939,1120,1121,1122,1125,1126,912],{},"Here we assume the Pocket ID network name is ",[464,1123,1124],{},"pocket-id_default",". You can check the connection by visiting SWAG's dashboard at ",[464,1127,1128],{},"http:\u002F\u002Fyourserverip:81",[451,1130,1132],{"id":1131},"create-the-subdomainconf-file","Create the subdomain.conf file",[391,1134,1135,1136,572],{},"In the Swag folders, create the file ",[464,1137,1138],{},"id.subdomain.conf",[741,1140,1142,1143,1146,1147,1149],{"icon":462,"to":1141},"\u002Fserveex\u002Ffiles\u002Ffile-browser-quantum","✨ ",[401,1144,1145],{},"Tip:"," Use ",[401,1148,209],{}," to navigate and edit files instead of using terminal commands.",[456,1151,1153],{"className":458,"code":1152,"filename":460,"language":461,"meta":462,"style":462},"sudo nano \u002Fsrv\u002Fdocker\u002Fswag\u002Fconfig\u002Fnginx\u002Fproxy-confs\u002Fid.subdomain.conf\n",[464,1154,1155],{"__ignoreMap":462},[467,1156,1157,1159,1162],{"class":469,"line":470},[467,1158,474],{"class":473},[467,1160,1161],{"class":477}," nano",[467,1163,1164],{"class":477}," \u002Fsrv\u002Fdocker\u002Fswag\u002Fconfig\u002Fnginx\u002Fproxy-confs\u002Fid.subdomain.conf\n",[391,1166,1167],{},"Paste the following configuration:",[456,1169,1173],{"className":1170,"code":1171,"filename":1138,"language":1172,"meta":462,"style":462},"language-nginx shiki shiki-themes github-dark material-theme github-dark","## Version 2023\u002F12\u002F19\n\nserver {\n    listen 443 ssl;\n    listen [::]:443 ssl;\n\n    server_name id.*;\n\n    include \u002Fconfig\u002Fnginx\u002Fssl.conf;\n\n    client_max_body_size 0;\n\n    location \u002F {\n        include \u002Fconfig\u002Fnginx\u002Fproxy.conf;\n        include \u002Fconfig\u002Fnginx\u002Fresolver.conf;\n        set $upstream_app pocket-id;\n        set $upstream_port 1411;\n        set $upstream_proto http;\n        proxy_pass $upstream_proto:\u002F\u002F$upstream_app:$upstream_port;\n    }\n}\n","nginx",[464,1174,1175,1180,1184,1193,1207,1216,1220,1230,1234,1244,1248,1258,1262,1273,1283,1292,1305,1319,1331,1354,1360],{"__ignoreMap":462},[467,1176,1177],{"class":469,"line":470},[467,1178,1179],{"class":771},"## Version 2023\u002F12\u002F19\n",[467,1181,1182],{"class":469,"line":547},[467,1183,1064],{"emptyLinePlaceholder":1063},[467,1185,1186,1190],{"class":469,"line":558},[467,1187,1189],{"class":1188},"sAoO4","server",[467,1191,1192],{"class":815}," {\n",[467,1194,1195,1199,1201,1204],{"class":469,"line":566},[467,1196,1198],{"class":1197},"sJPTy","    listen ",[467,1200,979],{"class":508},[467,1202,1203],{"class":815}," ssl",[467,1205,1206],{"class":554},";\n",[467,1208,1209,1211,1214],{"class":469,"line":578},[467,1210,1198],{"class":1197},[467,1212,1213],{"class":815},"[::]:443 ssl",[467,1215,1206],{"class":554},[467,1217,1218],{"class":469,"line":589},[467,1219,1064],{"emptyLinePlaceholder":1063},[467,1221,1222,1225,1228],{"class":469,"line":600},[467,1223,1224],{"class":1197},"    server_name ",[467,1226,1227],{"class":815},"id.*",[467,1229,1206],{"class":554},[467,1231,1232],{"class":469,"line":608},[467,1233,1064],{"emptyLinePlaceholder":1063},[467,1235,1236,1239,1242],{"class":469,"line":617},[467,1237,1238],{"class":1197},"    include ",[467,1240,1241],{"class":815},"\u002Fconfig\u002Fnginx\u002Fssl.conf",[467,1243,1206],{"class":554},[467,1245,1246],{"class":469,"line":625},[467,1247,1064],{"emptyLinePlaceholder":1063},[467,1249,1250,1253,1256],{"class":469,"line":633},[467,1251,1252],{"class":1197},"    client_max_body_size ",[467,1254,1255],{"class":508},"0",[467,1257,1206],{"class":554},[467,1259,1260],{"class":469,"line":641},[467,1261,1064],{"emptyLinePlaceholder":1063},[467,1263,1264,1267,1270],{"class":469,"line":649},[467,1265,1266],{"class":1188},"    location",[467,1268,1269],{"class":473}," \u002F ",[467,1271,1272],{"class":815},"{\n",[467,1274,1275,1278,1281],{"class":469,"line":657},[467,1276,1277],{"class":1197},"        include ",[467,1279,1280],{"class":815},"\u002Fconfig\u002Fnginx\u002Fproxy.conf",[467,1282,1206],{"class":554},[467,1284,1285,1287,1290],{"class":469,"line":709},[467,1286,1277],{"class":1197},[467,1288,1289],{"class":815},"\u002Fconfig\u002Fnginx\u002Fresolver.conf",[467,1291,1206],{"class":554},[467,1293,1294,1297,1300,1303],{"class":469,"line":720},[467,1295,1296],{"class":1197},"        set ",[467,1298,1299],{"class":554},"$",[467,1301,1302],{"class":815},"upstream_app pocket-id",[467,1304,1206],{"class":554},[467,1306,1307,1309,1311,1314,1317],{"class":469,"line":731},[467,1308,1296],{"class":1197},[467,1310,1299],{"class":554},[467,1312,1313],{"class":815},"upstream_port ",[467,1315,1316],{"class":508},"1411",[467,1318,1206],{"class":554},[467,1320,1322,1324,1326,1329],{"class":469,"line":1321},18,[467,1323,1296],{"class":1197},[467,1325,1299],{"class":554},[467,1327,1328],{"class":815},"upstream_proto http",[467,1330,1206],{"class":554},[467,1332,1334,1337,1339,1342,1344,1347,1349,1352],{"class":469,"line":1333},19,[467,1335,1336],{"class":1197},"        proxy_pass ",[467,1338,1299],{"class":554},[467,1340,1341],{"class":815},"upstream_proto:\u002F\u002F",[467,1343,1299],{"class":554},[467,1345,1346],{"class":815},"upstream_app:",[467,1348,1299],{"class":554},[467,1350,1351],{"class":815},"upstream_port",[467,1353,1206],{"class":554},[467,1355,1357],{"class":469,"line":1356},20,[467,1358,1359],{"class":815},"    }\n",[467,1361,1363],{"class":469,"line":1362},21,[467,1364,1365],{"class":815},"}\n",[1367,1368,1369],"caution",{},"Don't put Pocket ID behind another authentication layer (TinyAuth, HTTP auth...). It's the identity provider itself, so locking it away would prevent anyone, including you, from logging in.",[391,1371,1372,1373,1377,1378,1381,1382,1385],{},"Press ",[1374,1375],"kbd",{"value":1376},"Ctrl+O",", then ",[1374,1379],{"value":1380},"Enter"," to save, and ",[1374,1383],{"value":1384},"Ctrl+X"," to exit.",[451,1387,1389],{"id":1388},"visit-your-new-subdomain","Visit your new subdomain",[391,1391,1392,1393,1395],{},"Wait a few minutes, then open ",[464,1394,873],{}," in your browser.",[1367,1397,1398,1401],{},[401,1399,1400],{},"If it fails:"," check your firewall rules.",[451,1403,916],{"id":1404},"done-1",[438,1406,1408],{"id":1407},"registering-an-oidc-client","Registering an OIDC client",[391,1410,1411,1412,1414],{},"To let another app (e.g. ",[394,1413,137],{"href":417},") log in through Pocket ID, you need to register it as an OIDC client:",[447,1416,1417,1421,1426,1430,1444,1448,1459],{"level":449},[451,1418,1420],{"id":1419},"log-in-to-pocket-id","Log in to Pocket ID",[391,1422,931,1423,1425],{},[464,1424,873],{}," and log in with your passkey.",[451,1427,1429],{"id":1428},"create-the-oidc-client","Create the OIDC client",[391,1431,931,1432,1436,1437,1440,1441,1443],{},[1433,1434,1435],"em",{},"Administration > OIDC Clients",", then click ",[1433,1438,1439],{},"Add OIDC Client",". Fill in a name (e.g. ",[464,1442,137],{},") and the app's callback URL (provided by the app you're protecting).",[451,1445,1447],{"id":1446},"save-your-client-credentials","Save your client credentials",[391,1449,1450,1451,1454,1455,1458],{},"Save, then copy the generated ",[401,1452,1453],{},"Client ID"," and ",[401,1456,1457],{},"Client Secret",". You'll need them in the other app's configuration.",[451,1460,916],{"id":1461},"done-2",[438,1463,1465],{"id":1464},"connecting-pocket-id-to-tinyauth","Connecting Pocket ID to TinyAuth",[391,1467,1468,1470],{},[394,1469,137],{"href":417}," can delegate its login to Pocket ID instead of (or alongside) its local username\u002Fpassword, so anyone visiting a protected app authenticates with a passkey and gets forwarded through.",[447,1472,1473,1477,1487,1495,1499,1509,1523,1526,1604,1658,1666,1670,1677,1687],{"level":449},[451,1474,1476],{"id":1475},"register-tinyauth-as-an-oidc-client","Register TinyAuth as an OIDC client",[391,1478,1479,1483,1484,1486],{},[394,1480,1482],{"href":1481},"#registering-an-oidc-client","Register an OIDC client"," named ",[464,1485,137],{},", using this callback URL:",[456,1488,1493],{"className":1489,"code":1491,"language":1492,"meta":462},[1490],"language-text","https:\u002F\u002Ftinyauth.mydomain.com\u002Fapi\u002Foauth\u002Fcallback\u002Fpocketid\n","text",[464,1494,1491],{"__ignoreMap":462},[451,1496,1498],{"id":1497},"add-the-pocket-id-provider-in-tinyauth","Add the Pocket ID provider in TinyAuth",[391,1500,1501,1502,1454,1504,1506,1507,796],{},"Copy the ",[401,1503,1453],{},[401,1505,1457],{}," Pocket ID gives you, then edit TinyAuth's ",[464,1508,515],{},[456,1510,1512],{"className":458,"code":1511,"filename":460,"language":461,"meta":462,"style":462},"sudo nano \u002Fsrv\u002Fdocker\u002Ftinyauth\u002F.env\n",[464,1513,1514],{"__ignoreMap":462},[467,1515,1516,1518,1520],{"class":469,"line":470},[467,1517,474],{"class":473},[467,1519,1161],{"class":477},[467,1521,1522],{"class":477}," \u002Fsrv\u002Fdocker\u002Ftinyauth\u002F.env\n",[391,1524,1525],{},"Add the following:",[456,1527,1529],{"className":799,"code":1528,"filename":515,"language":801,"meta":462,"style":462},"TINYAUTH_OAUTH_PROVIDERS_POCKETID_NAME=Pocket ID\nTINYAUTH_OAUTH_PROVIDERS_POCKETID_CLIENTID=\nTINYAUTH_OAUTH_PROVIDERS_POCKETID_CLIENTSECRET=\nTINYAUTH_OAUTH_PROVIDERS_POCKETID_AUTHURL=https:\u002F\u002Fid.mydomain.com\u002Fauthorize\nTINYAUTH_OAUTH_PROVIDERS_POCKETID_TOKENURL=https:\u002F\u002Fid.mydomain.com\u002Fapi\u002Foidc\u002Ftoken\nTINYAUTH_OAUTH_PROVIDERS_POCKETID_USERINFOURL=https:\u002F\u002Fid.mydomain.com\u002Fapi\u002Foidc\u002Fuserinfo\nTINYAUTH_OAUTH_PROVIDERS_POCKETID_REDIRECTURL=https:\u002F\u002Ftinyauth.mydomain.com\u002Fapi\u002Foauth\u002Fcallback\u002Fpocketid\nTINYAUTH_OAUTH_PROVIDERS_POCKETID_SCOPES=openid email profile\n",[464,1530,1531,1541,1548,1555,1565,1575,1585,1594],{"__ignoreMap":462},[467,1532,1533,1536,1538],{"class":469,"line":470},[467,1534,1535],{"class":808},"TINYAUTH_OAUTH_PROVIDERS_POCKETID_NAME",[467,1537,812],{"class":554},[467,1539,1540],{"class":815},"Pocket ID\n",[467,1542,1543,1546],{"class":469,"line":547},[467,1544,1545],{"class":808},"TINYAUTH_OAUTH_PROVIDERS_POCKETID_CLIENTID",[467,1547,824],{"class":554},[467,1549,1550,1553],{"class":469,"line":558},[467,1551,1552],{"class":808},"TINYAUTH_OAUTH_PROVIDERS_POCKETID_CLIENTSECRET",[467,1554,824],{"class":554},[467,1556,1557,1560,1562],{"class":469,"line":566},[467,1558,1559],{"class":808},"TINYAUTH_OAUTH_PROVIDERS_POCKETID_AUTHURL",[467,1561,812],{"class":554},[467,1563,1564],{"class":815},"https:\u002F\u002Fid.mydomain.com\u002Fauthorize\n",[467,1566,1567,1570,1572],{"class":469,"line":578},[467,1568,1569],{"class":808},"TINYAUTH_OAUTH_PROVIDERS_POCKETID_TOKENURL",[467,1571,812],{"class":554},[467,1573,1574],{"class":815},"https:\u002F\u002Fid.mydomain.com\u002Fapi\u002Foidc\u002Ftoken\n",[467,1576,1577,1580,1582],{"class":469,"line":589},[467,1578,1579],{"class":808},"TINYAUTH_OAUTH_PROVIDERS_POCKETID_USERINFOURL",[467,1581,812],{"class":554},[467,1583,1584],{"class":815},"https:\u002F\u002Fid.mydomain.com\u002Fapi\u002Foidc\u002Fuserinfo\n",[467,1586,1587,1590,1592],{"class":469,"line":600},[467,1588,1589],{"class":808},"TINYAUTH_OAUTH_PROVIDERS_POCKETID_REDIRECTURL",[467,1591,812],{"class":554},[467,1593,1491],{"class":815},[467,1595,1596,1599,1601],{"class":469,"line":608},[467,1597,1598],{"class":808},"TINYAUTH_OAUTH_PROVIDERS_POCKETID_SCOPES",[467,1600,812],{"class":554},[467,1602,1603],{"class":815},"openid email profile\n",[836,1605,1606,1614],{},[839,1607,1608],{},[842,1609,1610,1612],{},[845,1611,847],{},[845,1613,850],{},[855,1615,1616,1628,1640],{},[842,1617,1618,1625],{},[860,1619,1620],{},[464,1621,1622],{"className":799,"language":801,"style":462},[467,1623,1624],{"class":815},"CLIENTID",[860,1626,1627],{},"The client ID copied from Pocket ID",[842,1629,1630,1637],{},[860,1631,1632],{},[464,1633,1634],{"className":799,"language":801,"style":462},[467,1635,1636],{"class":815},"CLIENTSECRET",[860,1638,1639],{},"The client secret copied from Pocket ID",[842,1641,1642,1655],{},[860,1643,1644,1269,1647,1269,1650],{},[464,1645,1646],{},"AUTHURL",[464,1648,1649],{},"TOKENURL",[464,1651,1652],{"className":799,"language":801,"style":462},[467,1653,1654],{"class":815},"USERINFOURL",[860,1656,1657],{},"Pocket ID's public URL, with the paths shown above",[391,1659,1372,1660,1377,1662,1381,1664,1385],{},[1374,1661],{"value":1376},[1374,1663],{"value":1380},[1374,1665],{"value":1384},[451,1667,1669],{"id":1668},"redeploy-the-stack","Redeploy the stack",[391,1671,1672,1673,1676],{},"Redeploy the TinyAuth stack. On your next visit to ",[464,1674,1675],{},"https:\u002F\u002Ftinyauth.mydomain.com",", you'll see a \"Login with Pocket ID\" option alongside the local login form.",[741,1678,1679,1680,1683,1684,1686],{"icon":462},"✨ To skip straight to Pocket ID and hide the local login form, add ",[464,1681,1682],{},"TINYAUTH_OAUTH_AUTOREDIRECT=pocketid"," to the same ",[464,1685,515],{}," file.",[451,1688,916],{"id":1689},"done-3",[391,1691,1692],{},"That's it! TinyAuth now offers passwordless login via Pocket ID for every app it protects.",[1694,1695,1696],"style",{},"html pre.shiki code .sEgDM, html code.shiki .sEgDM{--shiki-light:#B392F0;--shiki-default:#FFCB6B;--shiki-dark:#B392F0}html pre.shiki code .s11XM, html code.shiki .s11XM{--shiki-light:#9ECBFF;--shiki-default:#C3E88D;--shiki-dark:#9ECBFF}html pre.shiki code .sJWha, html code.shiki .sJWha{--shiki-light:#79B8FF;--shiki-default:#C3E88D;--shiki-dark:#79B8FF}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html pre.shiki code .swwWl, html code.shiki .swwWl{--shiki-light:#79B8FF;--shiki-default:#F78C6C;--shiki-dark:#79B8FF}html pre.shiki code .sRuoG, html code.shiki .sRuoG{--shiki-light:#85E89D;--shiki-default:#F07178;--shiki-dark:#85E89D}html pre.shiki code .s8jd1, html code.shiki .s8jd1{--shiki-light:#E1E4E8;--shiki-default:#89DDFF;--shiki-dark:#E1E4E8}html pre.shiki code .s8K8j, html code.shiki .s8K8j{--shiki-light:#9ECBFF;--shiki-default:#89DDFF;--shiki-dark:#9ECBFF}html pre.shiki code .sDvJj, html code.shiki .sDvJj{--shiki-light:#6A737D;--shiki-light-font-style:inherit;--shiki-default:#546E7A;--shiki-default-font-style:italic;--shiki-dark:#6A737D;--shiki-dark-font-style:inherit}html pre.shiki code .szyEh, html code.shiki .szyEh{--shiki-light:#F97583;--shiki-default:#F07178;--shiki-dark:#F97583}html pre.shiki code .slcoZ, html code.shiki .slcoZ{--shiki-light:#E1E4E8;--shiki-default:#EEFFFF;--shiki-dark:#E1E4E8}html pre.shiki code .s08Ry, html code.shiki .s08Ry{--shiki-light:#79B8FF;--shiki-default:#FF9CAC;--shiki-dark:#79B8FF}html pre.shiki code .sAoO4, html code.shiki .sAoO4{--shiki-light:#F97583;--shiki-default:#C792EA;--shiki-dark:#F97583}html pre.shiki code .sJPTy, html code.shiki .sJPTy{--shiki-light:#F97583;--shiki-default:#89DDFF;--shiki-dark:#F97583}",{"title":462,"searchDepth":547,"depth":547,"links":1698},[1699,1706,1707,1713,1719],{"id":440,"depth":547,"text":441,"children":1700},[1701,1702,1703,1704,1705],{"id":453,"depth":558,"text":454},{"id":488,"depth":558,"text":489},{"id":519,"depth":558,"text":520},{"id":789,"depth":558,"text":790},{"id":915,"depth":558,"text":916},{"id":919,"depth":547,"text":920},{"id":947,"depth":547,"text":948,"children":1708},[1709,1710,1711,1712],{"id":992,"depth":558,"text":993},{"id":1131,"depth":558,"text":1132},{"id":1388,"depth":558,"text":1389},{"id":1404,"depth":558,"text":916},{"id":1407,"depth":547,"text":1408,"children":1714},[1715,1716,1717,1718],{"id":1419,"depth":558,"text":1420},{"id":1428,"depth":558,"text":1429},{"id":1446,"depth":558,"text":1447},{"id":1461,"depth":558,"text":916},{"id":1464,"depth":547,"text":1465,"children":1720},[1721,1722,1723,1724],{"id":1475,"depth":558,"text":1476},{"id":1497,"depth":558,"text":1498},{"id":1668,"depth":558,"text":1669},{"id":1689,"depth":558,"text":916},[1726],"Djeex","Install Pocket ID, a lightweight self-hosted OIDC provider that lets you log in to your other apps with a passkey instead of a password.","md",null,{},{"title":141,"description":1727},"bBbFyuRiZ_EtxWxKjBYG8Ed8I9oOLWMTRstebF1e7jk",[1734,1736],{"title":137,"path":138,"stem":139,"description":1735,"children":-1},"Install TinyAuth, a lightweight forward-auth proxy, and pair it with Pocket ID to add SSO login in front of your self-hosted apps. Protect your app behind Swag with forward-auth.",{"title":151,"path":152,"stem":153,"description":1737,"children":-1},"Install Uptime-Kuma to monitor your self-hosted services uptime, set up alerts, and optionally protect the dashboard with Tinyauth or Authentik",1788645845966]