Skip to content

Support Cloudflare Access OIDC login - #43

Merged
backnotprop merged 1 commit into
mainfrom
codex/cloudflare-access-oidc
Sep 6, 2026
Merged

Support Cloudflare Access OIDC login#43
backnotprop merged 1 commit into
mainfrom
codex/cloudflare-access-oidc

Conversation

@backnotprop

Copy link
Copy Markdown
Contributor

Summary

  • add typed Cloudflare generic OIDC deployment inputs and redacted Worker secret binding
  • preserve the existing WorkOS hosted-auth path and scoped API-key agent path
  • add a Cloudflare Access operator guide and copyable deployment configuration
  • cover path-based issuers, secret handling, and mutually exclusive providers

Verification

  • pnpm smoke
  • pnpm verify:site
  • pnpm check:cloudflare
  • pnpm verify:iteration

Release evidence

The generic OIDC path passes the real Keycloak integration. A live Cloudflare Access tenant round trip remains an explicit non-production verification step and is not claimed in the conformance ledger.

@backnotprop
backnotprop merged commit f47cded into main Sep 6, 2026
8 checks passed
@backnotprop
backnotprop deleted the codex/cloudflare-access-oidc branch September 6, 2026 16:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant