--- title: Set up Single Sign-On with GitHub description: Setting up Github SSO videoBanner: XjgN2WWFCX8 --- This guide explains how to set up Github Single Sign On (SSO) for Teleport. ## Prerequisites - Install Teleport and the `tctl` admin tool version >= (=teleport.version=). See [Installation](../../installation.mdx) for details. - Create and register a GitHub OAuth App. To do so, follow the instructions in GitHub's documentation. [Creating an OAuth App](https://docs.github.com/en/developers/apps/building-oauth-apps/creating-an-oauth-app) Ensure that your OAuth App's "Authentication callback URL" is `https://PROXY_ADDRESS/v1/webapi/github/`, where `PROXY_ADDRESS` is the public address of the Teleport Proxy Service. - Install Teleport and the `tctl` admin tool version >= (=teleport.version=). To download Teleport Enterprise, visit the [customer portal](https://dashboard.gravitational.com/web/login). - Create and register a GitHub OAuth App. To do so, follow the instructions in GitHub's documentation. [Creating an OAuth App](https://docs.github.com/en/developers/apps/building-oauth-apps/creating-an-oauth-app) Ensure that your OAuth App's "Authentication callback URL" is `https://PROXY_ADDRESS/v1/webapi/github/`, where `PROXY_ADDRESS` is the public address of the Teleport Proxy Service. - Sign up for a Teleport Cloud account. If you do not have one, visit the [sign up page](https://goteleport.com/signup/) to begin your free trial. - Create and register a GitHub OAuth App. To do so, follow the instructions in GitHub's documentation. [Creating an OAuth App](https://docs.github.com/en/developers/apps/building-oauth-apps/creating-an-oauth-app) Ensure that your OAuth App's "Authentication callback URL" is `https://PROXY_ADDRESS/v1/webapi/github/`, where `PROXY_ADDRESS` is the domain name of your Teleport Cloud tenant (e.g., mytenant.teleport.sh). (!docs/pages/includes/tctl.mdx!) ## Step 1/2. Create a GitHub authentication connector Define a GitHub authentication connector by creating a file called `github.yaml` with the following content: ```yaml kind: github version: v3 metadata: # Connector name that will be used with `tsh --auth=github login` name: github spec: # Client ID of your GitHub OAuth App client_id: # Client secret of your GitHub OAuth App client_secret: # Connector display name that will be shown on the Web UI login screen display: GitHub # Callback URL that will be called after successful authentication redirect_url: https:///v1/webapi/github/callback # Mapping of org/team memberships onto allowed logins and roles teams_to_logins: - organization: octocats # GitHub organization name team: admins # GitHub team name within that organization # Maps octocats/admins to the "access" Teleport role logins: - access ``` The values of `client_id`, `client_secret`, and `redirect_url` come from the GitHub OAuth App you created earlier. Teleport will request only the `read:org` OAuth scope. Read more about OAuth scopes in GitHub's documentation: [Github OAuth scopes](https://developer.github.com/apps/building-oauth-apps/understanding-scopes-for-oauth-apps/) Finally, create the connector using `tctl`: ```code $ tctl create github.yaml ``` When going through the GitHub authentication flow for the first time, the application must be granted access to all organizations that are present in the "teams to logins" mapping, otherwise Teleport will not be able to determine team memberships for these organizations. ## Step 2/2. Configure authentication preference Configure the Teleport Auth Service to enable the GitHub authentication connector. Create a file called `cap.yaml` with the following content: ```yaml kind: cluster_auth_preference metadata: name: cluster-auth-preference spec: type: github webauthn: rp_id: 'example.teleport.sh' version: v2 ``` Create the resource: ```code $ tctl create -f cap.yaml ```
You can also edit your Teleport configuration file to include the following: ```yaml # Snippet from /etc/teleport.yaml auth_service: authentication: type: github ```
You can now log in with Teleport using GitHub SSO. ## Troubleshooting (!docs/pages/includes/sso/loginerrortroubleshooting.mdx!)