> ## Documentation Index
> Fetch the complete documentation index at: https://ayakaleaf-pro.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication

<Info>
  This feature is developed by [yu-i-i/overleaf-cep](https://github.com/yu-i-i/overleaf-cep).
</Info>

There are 3 authentication methods supported. After configuration, you can login with the following options, as image below shows.

<Frame>
  <img src="https://mintcdn.com/ayakaleaf-pro/x9kfDjtWlyyhG_mR/images/on-premises/image-33.png?fit=max&auto=format&n=x9kfDjtWlyyhG_mR&q=85&s=fd0bdcc31b169d87dea8fc5fa612da9c" alt="" width="2526" height="1721" data-path="images/on-premises/image-33.png" />
</Frame>

We highly recommend you use OIDC, since this is the most general method.

<Columns cols={2}>
  <Column>
    <Card title="OIDC Authentication" icon="file-lines" href="/on-premises/configuration/overleaf-toolkit/authentication/oidc-authentication" horizontal />

    <Card title="LDAP Authentication" icon="file-lines" href="/on-premises/configuration/overleaf-toolkit/authentication/ldap-authentication" horizontal />
  </Column>

  <Column>
    <Card title="SAML Authentication" icon="file-lines" href="/on-premises/configuration/overleaf-toolkit/authentication/saml-authentication" horizontal />
  </Column>
</Columns>

### Global Configuration

The environment variable `EXTERNAL_AUTH` is required to enable the specific authentication module. This environment variable specifies which external authentication methods are activated. Available options are (in lower case):

* saml
* ldap
* oidc

### Suggestions for SSO

I tested saml, ldap, oauth for overleaf. Both saml, oauth works well in overleaf, but ldap, it depends. It can't works well for [https://docs.goauthentik.io/](https://docs.goauthentik.io/), but it works well in openLDAP ([https://github.com/rroemhild/docker-test-openldap](https://github.com/rroemhild/docker-test-openldap)).

<Info>
  We need to update passport-ldapauth, recently I am trying to test overleaf ldap with [https://goauthentik.io/](https://goauthentik.io/) , it failed. After I update "passport-ldapauth" to 3.0.0, everything works well.

  ```text theme={null}
  "passport-ldapauth": "^3.0.0",
  ```

  The origianlly one is 2.x.x, which is 6 years ago.
</Info>

I am not sure what's the reason, because we all depends on an external package to do LDAP (also saml, oauth) auth. If not worked, the situtation can be the same for overleaf server pro, becase we just passed all environment var to internal package, if there are some bugs, we have no idea currently.

**So I highly recommend our user to setup development enviornment to test SSO with all source code**, which is available at [Setup Develop Environment (Local)](/dev/environment/setup-develop-environment-local "mention"). In development environment, you can see all logs in terminal, which makes it convenient for debug usage.

\\

<br />


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.