[{"data":1,"prerenderedAt":148},["ShallowReactive",2],{"seo-verification":3,"blog-stirling-pdf-v3-oauth2-sso-free-no-enterprise-en":6},{"google":4,"bing":5},"EycwPY2XMyTkVzas3n1ygeNJFGAH513qrMjfDljzsMQ","",{"key":7,"data":8},"blog-stirling-pdf-v3-oauth2-sso-free-no-enterprise-en",{"id":9,"slug":10,"slugs":11,"title":15,"excerpt":16,"readTime":17,"views":18,"isPinned":19,"publishedAt":20,"updatedAt":21,"category":22,"categories":28,"featuredImage":30,"bgImage":31,"posterImage":32,"relatedSolution":33,"intro":36,"sections":37,"ctaTitle":84,"ctaBody":85,"ctaButton":86,"ctaUrl":87,"relatedPosts":88},422,"stirling-pdf-v3-oauth2-sso-free-no-enterprise",{"fr":12,"en":10,"ar":13,"es":14},"stirling-pdf-v3-sso-libre-enterprise-gratuit","stirling-pdf-v3-sso-oauth2-مجاني-بدون-enterprise","stirling-pdf-v3-oauth2-sso-gratuito-sin-enterprise","Stirling PDF v3: OAuth2 SSO is now free, no Enterprise lock","Since v3.0.0 (Sept. 2026), Stirling PDF's OAuth2 SSO is completely free. Configure it with Authentik or Keycloak in 15 minutes using three settings.yml blocks.",8,0,false,"2026-10-07T00:00:00+00:00","2026-10-07T23:07:24+00:00",{"id":23,"name":24,"slug":25,"color":26,"icon":27},7,"Self-hosting","self-hosting","bg-indigo-500\u002F10 text-indigo-400","cloud",[29],{"id":23,"name":24,"slug":25,"color":26,"icon":27},null,"\u002Fblog\u002Fcovers\u002Fbg.svg","\u002Fblog\u002Fcovers\u002Fstirling-pdf-v3-sso-libre-enterprise-gratuit-poster.svg",{"categorySlug":34,"appSlug":35},"collaboration-productivity","stirling-pdf","Until v2, Stirling PDF's OAuth2 SSO was an Enterprise-only feature: teams wanting to secure their instance with an identity provider had to pay or go without. PR #8137, merged in September 2026 and shipped in v3.0.0, removed that restriction — SSO is now available on every installation, for free, without changing plans. If your instance is running today without centralized authentication, you can fix that in fifteen minutes.",[38,42,52,55,68,71,74,78,81],{"type":39,"title":40,"body":41},"h2","Enterprise SSO became free in v3","Stirling PDF packages over 50 PDF operations — merge, split, compress, convert, OCR, sign, reorder pages — into a self-hosted web interface. Since its launch, the tool has grown on GitHub (87,000 stars, MIT license) and established itself as the open source reference for team document processing.\n\nv2 compartmentalized features: basic operations were free, OAuth2 SSO and a few advanced functions were reserved for the Enterprise plan. This freemium model made commercial sense, but it created an uncomfortable situation for self-hosted teams: Stirling PDF reachable without a password on an open port, or with local accounts impossible to revoke from a central directory.\n\n**PR #8137** merged in September 2026 and reorganized the feature grid. **v3.0.0** (release notes: \u003Ca href=\"https:\u002F\u002Fgithub.com\u002FStirling-Tools\u002FStirling-PDF\u002Freleases\u002Ftag\u002Fv3.0.0\">github.com\u002FStirling-Tools\u002FStirling-PDF\u002Freleases\u002Ftag\u002Fv3.0.0\u003C\u002Fa>) shipped this change, confirmed stable in **v3.1.0** (October 5, 2026). Result: `SECURITY_OAUTH2_ENABLED=true` works on any installation ≥ v3.0.0, without a license key, without a paid plan.",{"type":43,"title":44,"items":45},"ul","What free SSO changes in practice",[46,47,48,49,50,51],"Centralized access: all team members authenticate through your existing identity provider (Authentik, Keycloak, Zitadel, Okta…) — no local accounts to create or revoke manually.","Immediate revocation: disabling an account in your IdP closes access to Stirling PDF at the same time as the rest of your stack — no orphaned accounts.","Compliance: access is logged on the IdP side, not in Stirling PDF. Centralized audit trail, no additional configuration required.","Local form disabled: a single variable (`SECURITY_OAUTH2_AUTO_CREATE_USER=false` combined with disabling the login form) prevents any SSO bypass.","PKCE support: v3 properly implements the PKCE flow — IdPs that require it (Authentik in particular) work without special configuration.","Non-destructive update: enabling SSO on an existing instance does not delete processed files or history.",{"type":39,"title":53,"body":54},"Prerequisites","Before starting:\n\n**Stirling PDF ≥ v3.0.0 already deployed.** If your instance is running v2.x, update it (`docker compose pull && docker compose up -d`) and verify with `docker compose logs stirling-pdf | grep version`.\n\n**An operational OIDC identity provider.** This guide covers the two most common IdPs in self-hosted stacks: **Authentik** (a dedicated container, typically on the same VPS) and **Keycloak** (deployed separately, recommended for multi-application environments). If you don't have an IdP yet, the guide \u003Ca href=\"\u002Fblog\u002Fself-host-authentik-vps\">Hosting Authentik on a VPS\u003C\u002Fa> covers the complete installation.\n\n**A reverse proxy with active TLS.** Stirling PDF must be served over HTTPS — OAuth2 session cookies are `Secure` by default. nginx, Caddy, and Traefik all work without modification.\n\n**Resources: minimum 1 vCPU \u002F 2 GB RAM.** OCR and complex PDF conversion are resource-intensive — plan for 2 vCPU \u002F 4 GB for team use above 5 simultaneous users.",{"type":56,"title":57,"steps":58},"steps","Enabling SSO in Stirling PDF",[59,62,65],{"title":60,"body":61},"Update to v3.0.0 or higher","If your `docker-compose.yml` still points to the `frooodle\u002Fs-pdf:latest` image or a pinned version ≤ 2.x, first update the image:\n\n```bash\ndocker compose pull stirling-pdf\ndocker compose up -d stirling-pdf\ndocker compose logs stirling-pdf --tail=20\n```\n\nVerify that the `Stirling-PDF version` line shows `3.0.0` or higher before continuing.",{"title":63,"body":64},"Add OAuth2 variables to settings.yml","Stirling PDF loads its configuration from `.\u002Fconfigs\u002Fsettings.yml` (path of the volume mounted in the compose). Open this file and add or complete the `security` block:\n\n```bash\nsecurity:\n  enableLogin: true\n  oauth2:\n    enabled: true\n    provider: oidc\n    issuer: https:\u002F\u002Fauthentik.your-domain.com\u002Fapplication\u002Fo\u002Fstirling-pdf\u002F\n    clientId: YOUR_CLIENT_ID\n    clientSecret: YOUR_CLIENT_SECRET\n    scopes: openid,profile,email\n    useAsUsername: email\n    autoCreateUser: true\n```\n\nAll six variables are required. `SECURITY_OAUTH2_USE_AS_USERNAME` determines which OIDC token field serves as the username in Stirling PDF — `email` is the usual choice, `preferred_username` also works if your IdP provides it.\n\nAlternatively, these variables can be passed directly in `docker-compose.yml` under `environment:` with the `SECURITY_OAUTH2_` prefix:\n\n```bash\nenvironment:\n  SECURITY_OAUTH2_ENABLED: \"true\"\n  SECURITY_OAUTH2_PROVIDER: oidc\n  SECURITY_OAUTH2_ISSUER: https:\u002F\u002Fauthentik.your-domain.com\u002Fapplication\u002Fo\u002Fstirling-pdf\u002F\n  SECURITY_OAUTH2_CLIENT_ID: YOUR_CLIENT_ID\n  SECURITY_OAUTH2_CLIENT_SECRET: YOUR_CLIENT_SECRET\n  SECURITY_OAUTH2_SCOPES: openid,profile,email\n  SECURITY_OAUTH2_USE_AS_USERNAME: email\n  SECURITY_OAUTH2_AUTO_CREATE_USER: \"true\"\n```",{"title":66,"body":67},"Restart the container and verify logs","Apply the configuration:\n\n```bash\ndocker compose restart stirling-pdf\ndocker compose logs stirling-pdf --follow --tail=30\n```\n\nLook for the `OAuth2 SSO enabled` line in the startup logs. If you see `Error loading OAuth2 issuer metadata`, the OIDC discovery endpoint (`\u002F.well-known\u002Fopenid-configuration`) is unreachable from the container — verify that the `issuer` URL is reachable via Docker networking.\n\nThen test that the redirect endpoint exists:\n\n```bash\ncurl -I https:\u002F\u002Fpdf.your-domain.com\u002Foauth2\u002Fauthorization\u002Foidc\n```\n\nExpected response: `HTTP\u002F2 302` to your IdP's authorization URL. A `404` means SSO is not activated (variable not read or container not restarted).",{"type":39,"title":69,"body":70},"Configuring Authentik as identity provider","In the Authentik admin interface (`https:\u002F\u002Fauthentik.your-domain.com\u002Fif\u002Fadmin\u002F`):\n\n**1. Create an OAuth2\u002FOIDC Provider**\n\nGo to **Applications → Providers → Create**. Choose **OAuth2\u002FOpenID Connect Provider**. Give it a name (e.g. `stirling-pdf-provider`). In the **Redirect URIs** field, enter exactly:\n\n```bash\nhttps:\u002F\u002Fpdf.your-domain.com\u002Flogin\u002Foauth2\u002Fcode\u002Foidc\n```\n\nEnable **PKCE** (Proof Key for Code Exchange) if the checkbox is available — Authentik requires it by default since version 2024.x. Leave scopes on `openid`, `profile`, `email`.\n\nNote the generated **Client ID** and **Client Secret** — these are the values to copy into `settings.yml`.\n\n**2. Create the Application**\n\nGo to **Applications → Applications → Create**. Name it `Stirling PDF`, select the Provider created in the previous step. Save.\n\n**3. Get the issuer URL**\n\nAuthentik's OIDC discovery URL follows the pattern:\n\n```bash\nhttps:\u002F\u002Fauthentik.your-domain.com\u002Fapplication\u002Fo\u002Fstirling-pdf\u002F\n```\n\nWhere `stirling-pdf` is the Application **slug** (not the Provider). Verify by opening `https:\u002F\u002Fauthentik.your-domain.com\u002Fapplication\u002Fo\u002Fstirling-pdf\u002F.well-known\u002Fopenid-configuration` in a browser — you should receive a valid JSON with `authorization_endpoint`.",{"type":39,"title":72,"body":73},"Configuring Keycloak as identity provider","In the Keycloak admin console (`https:\u002F\u002Fkeycloak.your-domain.com\u002Fadmin\u002F`):\n\n**1. Select the Realm**\n\nChoose the realm that hosts your users (e.g. `master` for internal use, or a dedicated realm `internal-apps`).\n\n**2. Create an OIDC Client**\n\nGo to **Clients → Create client**. Fill in:\n- **Client ID**: `stirling-pdf` (free value, but must be reported in `settings.yml`)\n- **Client Protocol**: `openid-connect`\n- **Access Type**: `confidential`\n\nIn the **Settings** tab, add the Redirect URI:\n\n```bash\nhttps:\u002F\u002Fpdf.your-domain.com\u002Flogin\u002Foauth2\u002Fcode\u002Foidc\n```\n\nEnable **Standard Flow** and disable **Implicit Flow**.\n\n**3. Get the Client Secret**\n\n**Credentials** tab → copy the **Secret** value.\n\n**4. Keycloak issuer URL**\n\nThe URL follows the pattern:\n\n```bash\nhttps:\u002F\u002Fkeycloak.your-domain.com\u002Frealms\u002FYOUR_REALM\n```\n\nVerify by opening `https:\u002F\u002Fkeycloak.your-domain.com\u002Frealms\u002FYOUR_REALM\u002F.well-known\u002Fopenid-configuration`.",{"type":75,"title":76,"body":77},"tip","Hardening: disable the local login form after SSO","Once SSO is validated and all your users migrated, it is recommended to disable the local password login form — which remains active by default even with OAuth2 enabled. Add to `settings.yml`:\n\n```bash\nsecurity:\n  enableLogin: true\n  loginMethod: oauth2\n```\n\nDisabling the local method prevents any SSO bypass through the form. Keep an emergency admin account in your IdP before applying this configuration — if your IdP becomes unavailable, you will no longer be able to log in.",{"type":39,"title":79,"body":80},"Troubleshooting common errors","**`redirect_uri mismatch`** — The URI registered in the provider does not exactly match what Stirling PDF sends. The expected value is `https:\u002F\u002Fpdf.your-domain.com\u002Flogin\u002Foauth2\u002Fcode\u002Foidc`, no trailing slash, HTTPS required. Check for invisible spaces or characters in your IdP field.\n\n**`PKCE required` or `code_challenge_method unsupported`** — Authentik requires PKCE by default since 2024.x. If your Stirling PDF version is \u003C 3.0.0, it does not support PKCE — update it. On v3, the PKCE flow is natively supported.\n\n**Cross-domain cookies lost after IdP redirect** — If Stirling PDF is served on a different subdomain from your IdP, check that your reverse proxy is not injecting `SameSite=Strict` on session cookies. The correct value is `SameSite=Lax`. Symptom: the redirect from the IdP results in a blank page or redirect loop.\n\n**`Error loading OAuth2 issuer metadata`** on startup — The Stirling PDF container cannot reach your IdP's discovery endpoint. Common causes: isolated Docker network (the container cannot resolve the IdP domain name), untrusted self-signed TLS certificate, or IdP is down. Test from the container: `docker compose exec stirling-pdf curl -s https:\u002F\u002Fauthentik.your-domain.com\u002Fapplication\u002Fo\u002Fstirling-pdf\u002F.well-known\u002Fopenid-configuration`.\n\n**User logs in but sees `403 Forbidden`** — `SECURITY_OAUTH2_AUTO_CREATE_USER` is `false` (default) and the user doesn't yet exist in Stirling PDF. Set it to `true` while accounts are created on first login, or create users manually from the Stirling PDF admin interface.",{"type":39,"title":82,"body":83},"SSO at no cost, one block at a time","SSO is no longer a selling point of a paid edition — it is a three-block configuration in a YAML file. v3.0.0 made this change permanent, and v3.1.0 (October 5, 2026) confirms the stability of the new behavior.\n\nIf your Stirling PDF instance is exposed to your team without centralized authentication today, the fix takes one container update, three environment variables, and two configuration screens in your IdP. The return: instant revocation, centralized audit trail, and one uncontrolled access vector closed.\n\nTo go further on the open source IdPs covered here, the guides \u003Ca href=\"\u002Fblog\u002Fself-host-authentik-vps\">Hosting Authentik on a VPS\u003C\u002Fa> and \u003Ca href=\"\u002Fblog\u002Fauthentik-vs-authelia-keycloak-sso-vps-2026\">Authentik, Authelia or Keycloak: choosing your SSO\u003C\u002Fa> cover the deployment and trade-offs of each solution.","Deploy Stirling PDF with SSO on your VPS","Provision a ready-to-use Stirling PDF environment — Docker Compose, reverse proxy, and SSO configuration included. Connect your OIDC provider and secure team access from the first startup.","Activate this solution","\u002Fmarketplace\u002Fcollaboration-productivity\u002Fstirling-pdf",[89,106,129],{"id":90,"slug":91,"slugs":92,"title":96,"excerpt":97,"readTime":98,"views":18,"isPinned":19,"publishedAt":99,"updatedAt":100,"category":101,"categories":102,"featuredImage":30,"bgImage":31,"posterImage":104,"relatedSolution":105},178,"self-host-stirling-pdf-on-a-vps-50-pdf-operations-no-cloud",{"fr":93,"en":91,"ar":94,"es":95},"self-host-stirling-pdf-vps","استضافة-stirling-pdf-على-vps-أكثر-من-50-عملية-بلا-سحابة","alojar-stirling-pdf-en-un-vps","Self-Host Stirling PDF on a VPS: 50+ PDF Operations, No Cloud","Self-host Stirling PDF on a VPS — the #1 PDF app on GitHub (87 k stars, MIT). Merge, split, compress, convert, OCR and 50+ operations. No cloud upload, no subscription.",5,"2026-07-13T00:00:00+00:00","2026-09-07T11:26:10+00:00",{"id":23,"name":24,"slug":25,"color":26,"icon":27},[103],{"id":23,"name":24,"slug":25,"color":26,"icon":27},"\u002Fblog\u002Fcovers\u002Fself-host-stirling-pdf-vps-poster.svg",{"categorySlug":34,"appSlug":35},{"id":107,"slug":108,"slugs":109,"title":113,"excerpt":114,"readTime":115,"views":116,"isPinned":19,"publishedAt":117,"updatedAt":118,"category":119,"categories":124,"featuredImage":30,"bgImage":31,"posterImage":126,"relatedSolution":127},162,"self-host-authelia-on-a-vps-mfa-and-sso-for-your-whole-stack",{"fr":110,"en":108,"ar":111,"es":112},"self-host-authelia-vps","استضافة-authelia-على-vps-مصادقة-ثنائية-ودخول-موحد-لمنظومتك","alojar-authelia-en-un-vps","Self-hosting Authelia on a VPS: MFA and SSO for your entire stack","Deploy Authelia on a VPS with Docker Compose: TOTP, WebAuthn\u002Fpasskey, OIDC, LLDAP migration, Prometheus monitoring, and comparison with Authentik.",10,3,"2026-07-04T00:00:00+00:00","2026-09-24T12:27:51+00:00",{"id":17,"name":120,"slug":121,"color":122,"icon":123},"Security & Monitoring","securite-monitoring","bg-rose-500\u002F10 text-rose-400","security",[125],{"id":17,"name":120,"slug":121,"color":122,"icon":123},"\u002Fblog\u002Fcovers\u002Fself-host-authelia-vps-poster.svg",{"categorySlug":123,"appSlug":128},"authelia",{"id":130,"slug":131,"slugs":132,"title":136,"excerpt":137,"readTime":138,"views":139,"isPinned":19,"publishedAt":140,"updatedAt":100,"category":141,"categories":142,"featuredImage":30,"bgImage":31,"posterImage":144,"relatedSolution":145},272,"authentik-authelia-or-keycloak-choosing-your-sso-on-vps",{"fr":133,"en":131,"ar":134,"es":135},"authentik-vs-authelia-keycloak-sso-vps-2026","authentik-أو-authelia-أو-keycloak-اختيار-sso-على-vps","authentik-authelia-o-keycloak-elegir-sso-en-vps","Authentik, Authelia or Keycloak: Choosing Your SSO on VPS","Authentik, Authelia or Keycloak on VPS: compare real memory footprint, covered protocols and Keycloak 26.7.1 CVEs to choose the right self-hosted SSO.",6,1,"2026-08-16T00:00:00+00:00",{"id":17,"name":120,"slug":121,"color":122,"icon":123},[143],{"id":17,"name":120,"slug":121,"color":122,"icon":123},"\u002Fblog\u002Fcovers\u002Fauthentik-vs-authelia-keycloak-sso-vps-2026-poster.svg",{"categorySlug":146,"appSlug":147},"cybersecurity-bastion","authentik",1791414838032]