identity-service documentation
Welcome to Shellui identity-service — a Django backend that provides Shellui-compatible authentication under /api/v1/*.
Current docs target: release v0.6.0 on develop (Redis shared cache, enterprise SCIM).
Live site: https://docs.shellui.com/identity · Project setup: README.md on GitHub.
v0.6.0 highlights
| Area | Summary |
|---|---|
| OAuth login | Identity-hosted authorize/callback, session-code vs legacy fragment delivery, redirect allowlist, company OAuth clients, hosting sync |
| Social login providers | django-allauth catalog (primary starters + full list), enablement checklist, IdP callback URLs |
| SCIM | Opt-in enterprise provisioning (Users + Groups + nested groups), per-company bearer tokens |
| Shellui webhooks | Domain events → signed webhooks, DB outbox + retry_webhooks |
| n8n integration | Webhook node setup, signature verification, retries |
| Configuration | JWT (iss/aud, RS256, HS256 legacy), CORS, REDIS_URL, Postgres timeouts, Gunicorn, /health/live, SCIM_ENABLED, TRUSTED_PROXY_IPS, token delivery |
| Company access | Public, domain, and invitation-only join modes after OAuth |
| JWKS | RS256 signing and /.well-known/jwks.json |
| Security hardening | Rate limits, transport defaults, trusted proxies |
| Metrics | JWT and personal access token access to /api/v1/metrics |
| Releases | Docker Hub tags and publish checklist |
Quick start (operators)
- Copy
.env.exampleand setSECRET_KEY, JWT keys,JWT_ISSUER, andJWT_AUDIENCEfor production. - Point load balancers at
GET /health/live. - Register IdP callbacks at
{identity-host}/api/v1/oauth/callbackand configure company redirect allowlists — OAuth login. - For multi-worker production, set
REDIS_URL— Configuration. - For SCIM, run migrations and create a company SCIM token — SCIM.
Preview these docs locally
From the repository root:
cd tools/docusaurus
npm install
npm start
Open the URL printed by Docusaurus (default http://localhost:3000).