Skip to main content

identity-service documentation

Welcome to Shellui identity-service — a Django backend that provides Shellui-compatible authentication under /api/v1/*.

Current docs target: release v0.6.0 on develop (Redis shared cache, enterprise SCIM).

Live site: https://docs.shellui.com/identity · Project setup: README.md on GitHub.


v0.6.0 highlights​

AreaSummary
OAuth loginIdentity-hosted authorize/callback, session-code vs legacy fragment delivery, redirect allowlist, company OAuth clients, hosting sync
Social login providersdjango-allauth catalog (primary starters + full list), enablement checklist, IdP callback URLs
SCIMOpt-in enterprise provisioning (Users + Groups + nested groups), per-company bearer tokens
Shellui webhooksDomain events → signed webhooks, DB outbox + retry_webhooks
n8n integrationWebhook node setup, signature verification, retries
ConfigurationJWT (iss/aud, RS256, HS256 legacy), CORS, REDIS_URL, Postgres timeouts, Gunicorn, /health/live, SCIM_ENABLED, TRUSTED_PROXY_IPS, token delivery
Company accessPublic, domain, and invitation-only join modes after OAuth
JWKSRS256 signing and /.well-known/jwks.json
Security hardeningRate limits, transport defaults, trusted proxies
MetricsJWT and personal access token access to /api/v1/metrics
ReleasesDocker Hub tags and publish checklist

Quick start (operators)​

  1. Copy .env.example and set SECRET_KEY, JWT keys, JWT_ISSUER, and JWT_AUDIENCE for production.
  2. Point load balancers at GET /health/live.
  3. Register IdP callbacks at {identity-host}/api/v1/oauth/callback and configure company redirect allowlists — OAuth login.
  4. For multi-worker production, set REDIS_URL — Configuration.
  5. For SCIM, run migrations and create a company SCIM token — SCIM.

Preview these docs locally​

From the repository root:

cd tools/docusaurus
npm install
npm start

Open the URL printed by Docusaurus (default http://localhost:3000).