diff --git a/doc/integrations/sso/gitlab-sso.md b/doc/integrations/sso/gitlab-sso.md new file mode 100644 index 0000000000..c0cd6cb457 --- /dev/null +++ b/doc/integrations/sso/gitlab-sso.md @@ -0,0 +1,19 @@ +## Configuring GitLab Single-Sign-On + +The following steps can be used to configure Mattermost to use GitLab as a single-sign-on (SSO) service for team creation, account creation and sign-in. + +1. Login to your GitLab account and go to the Applications section either in Profile Settings or Admin Area. +2. Add a new application called "Mattermost" with the following as Redirect URIs: + * `/login/gitlab/complete` (example: http://localhost:8065/login/gitlab/complete) + * `/signup/gitlab/complete` + +3. Submit the application and copy the given _Id_ and _Secret_ into the appropriate _SSOSettings_ fields in config/config.json + +4. Also in config/config.json, set _Allow_ to `true` for the _gitlab_ section, leave _Scope_ blank and use the following for the endpoints: + * _AuthEndpoint_: `/oauth/authorize` (example http://localhost:3000/oauth/authorize) + * _TokenEndpoint_: `/oauth/token` + * _UserApiEndpoint_: `/api/v3/user` + +6. (Optional) If you would like to force all users to sign-up with GitLab only, in the _ServiceSettings_ section of config/config.json please set _AllowEmailSignUp_ to `false`. + +7. Restart your Mattermost server to see the changes take effect.