| title | Create a GitLab OAuth application |
|---|---|
| sidebar_position | 75 |
- GitLab account
- A local Minder server running with the
gitlab_providerfeature flag enabled (see Using feature flags)
-
Navigate to GitLab User Settings > Applications
-
Click Add new application and enter the following details:
- Name:
Minder(or any name you prefer) - Redirect URI (add both URIs, one per line):
http://localhost:8080/api/v1/auth/callback/gitlab/cli http://localhost:8080/api/v1/auth/callback/gitlab/web - Confidential: Yes (checked)
- Scopes: Check
api,read_user, andread_repository
- Name:
-
Click Save application. Copy the Application ID and Secret — the secret is only shown once.
-
Add the following to your
server-config.yamlunder theprovider:section:provider: gitlab: client_id: "YOUR_APPLICATION_ID" client_secret: "YOUR_SECRET" redirect_uri: "http://localhost:8080/api/v1/auth/callback/gitlab" webhook_secret: "a-random-secret-string" scopes: - "api" - "read_user" - "read_repository"
The
redirect_urishould be the base path without/clior/web— Minder appends the correct suffix automatically. -
Enable the
gitlab_providerfeature flag by creatingflags-config.yamlin the root of your Minder directory:gitlab_provider: variations: enabled: true disabled: false defaultRule: variation: enabled
-
(Re)start the Minder server:
make run-docker
-
Enroll the GitLab provider using the CLI:
minder provider enroll --class gitlab
A browser window will open to GitLab's OAuth authorization page. After authorizing, the browser will show Minder enrollment complete and the CLI will print
Provider enrolled successfully.
- GitLab support is currently only available on self-hosted Minder instances.
The hosted instance at
api.custcodian.devdoes not yet support GitLab enrollment. - Webhook-based event delivery requires an externally reachable URL. For local development, tools like ngrok can expose your local server.
- Token identity verification after enrollment is not yet implemented.