Skip to main content


Support level: Community

What is Gravitee


note API Management is a flexible, lightweight and blazing-fast Open Source solution that helps your organization control who, when and how users access your APIs.

It offers an easy to use GUI to setup proxies for APIs, rate limiting, api keys, caching, OAUTH rules, a portal that can be opened to the public for people to subscribe to APIs, and much more.


The following placeholders will be used:

  • is the FQDN of the Gravitee install.
  • is the FQDN of the authentik install.
  • applicationName is the Application name you set.

Step 1 - authentik

In authentik, under Providers, create an OAuth2/OpenID Provider with these settings:


Only settings that have been modified from default have been listed.

Protocol Settings

  • Name: applicationName
  • Client ID: Copy and Save this for Later
  • Client Secret: Copy and Save this for later
  • Redirect URIs/Origins: # Make sure to add the trailing / at the end, at the time of writing it does not work without it

Now, under Applications, create an application with the name applicationName and select the provider you've created above.

Step 2 - Gravitee

In the Gravitee Management Console, head to Organizations(!/organization/settings/identities) , under Console, Authentication, click Add an identity provider, select OpenID Connect, and fill in the following:


Only settings that have been modified from default have been listed.

  • Allow portal authentication to use this identity provider: enable this
  • Client ID: Client ID from step 1
  • Client Secret: Client Secret from step 1
  • Token Endpoint:
  • Authorize Endpoint:
  • Userinfo Endpoint:
  • Userinfo Logout Endpoint:
  • Scopes: email openid profile