update_settings
Modify OIDC proxy settings—issuer, audience, token expiry, PKCE, login mode, and SAML options—to control authentication behavior and token issuance.
Instructions
Update NanoIDP settings (issuer, audience, token expiry, SAML options, etc.). hooks: and plugins: (#185) are YAML-only, like secret_key and require_ui_login: they are reported by get_settings but cannot be changed here, since a command editable through the surface it observes would be a remote-execution primitive.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| issuer | No | OAuth2/OIDC issuer URL | |
| audience | No | Default token audience | |
| login_mode | No | Interactive login mode: 'password' (default) requires the configured password on /login, /authorize, /saml/sso and the device flow; 'persona' lists the configured users and logs in by selecting one, no password prompt. Opt-in, off by default - a local development/testing convenience, not an authentication mode for deployed environments. Orthogonal to 'security_profile' and to the OAuth password grant, which is unaffected either way. | |
| require_pkce | No | Reject /authorize requests without a PKCE code_challenge (#47) | |
| saml_sso_url | No | SAML SingleSignOnService location. Empty string clears it so it is derived again as <issuer>/saml/sso (#181) | |
| saml_entity_id | No | SAML IdP entityID. Empty string clears it so it is derived again from the effective issuer as <issuer>/saml (#181) | |
| verbose_logging | No | Include usernames/client_ids in log messages (dev convenience) | |
| issuer_allowlist | No | Origins (e.g. 'http://localhost:8000') allowed to be reflected back by 'issuer_from_request'. Empty (default) allows any Host header. A non-matching Host falls back to the fixed 'issuer'. | |
| saml_export_roles | No | Emit the user's roles as a SAML attribute (off by default) | |
| saml_export_groups | No | Emit the user's groups as a SAML attribute (off by default) | |
| issuer_from_request | No | Derive the issuer from each request's own Host header instead of the fixed 'issuer' (dev convenience for setups reachable under more than one hostname). MCP tools have no request of their own, so this only affects HTTP discovery/token/device-flow responses, never MCP ones. | |
| saml_c14n_algorithm | No | XML canonicalization algorithm: 'c14n' (1.0), 'c14n11' (1.1), or 'exc_c14n' (Exclusive 1.0) | |
| saml_sign_responses | No | Enable/disable SAML response signing | |
| strict_saml_binding | No | Enforce strict SAML binding compliance (reject GET with uncompressed data) | |
| saml_roles_attr_name | No | SAML attribute name for the roles (default: 'roles') | |
| saml_sp_certificates | No | PEM certificate files of SPs whose AuthnRequest signatures are accepted | |
| token_expiry_minutes | No | Token expiration in minutes | |
| saml_groups_attr_name | No | SAML attribute name for the groups (default: 'groups') | |
| refresh_token_rotation | No | Rotate refresh tokens: each refresh invalidates the consumed refresh token (#46) | |
| issuer_from_proxy_headers | No | Trust 'X-Forwarded-Proto'/'X-Forwarded-Host'/'X-Forwarded-For' from a single reverse-proxy hop in front of NanoIDP (applies werkzeug's ProxyFix). Only affects the 'issuer_from_request' derivation - and only when that toggle is also on; it always affects rate-limit client IP attribution regardless. Only enable this when NanoIDP is deployed directly behind exactly one trusted proxy - these headers are otherwise spoofable by any client. Takes effect on the next app restart, not the running process. | |
| device_verification_base_url | No | Fixed base URL for the device flow's verification_uri (e.g. 'https://idp.example.com'), used instead of the request-derived issuer so a backend/container caller's Host doesn't leak into a URL a human's browser can't reach. Only consulted when 'issuer_from_request' is on; empty string clears it back to following the request Host. | |
| saml_want_authn_requests_signed | No | Require and verify AuthnRequest signatures, both bindings (#69) |