You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Non-duplicate issue: I have searched existing Issues and confirmed there are no similar issues.
Read this first: I have fully read the section above, reviewed the docs at https://docs.newapi.ai/ and the project README, and asked AI first, confirming this is not a usage, configuration, or integration question, and that the current version cannot meet my needs.
Supported version: I have provided an exact version, commit, or image tag (not latest or unknown) and confirm this feature request is for an unmodified, supported version from this repository.
Not a third-party service: I confirm that this request is not exclusive to a third-party hosting site, relay, API service, or fork that has not been verified against the unmodified repository. Third-party instance issues must be reported to their operator.
Not pass-through: I confirm this is not a forwarding report after enabling pass-through; pass-through sends content as-is and does not go through new-api processing logic.
Channel and protocol boundary: I confirm this is not a feature request for a Coding Plan service, reverse-engineered channel, third-party API wrapper, Codex reverse-proxy endpoint, or treating Codex API-specific behavior as standard OpenAI API behavior. If first observed through such an interface, I have based the request on a standard API protocol supported by this repository.
Template intact: I have not removed any guidance or section headings from this template and will complete it as requested.
Maintainer time: I understand that maintainers have limited time. Do not paste unfiltered AI-generated text in the issue body or in later comments; extract the points needed for review first. Submissions that do not follow this template, or that omit the necessary points and cannot be reviewed, may be ignored or closed. Repeated submissions of this kind may result in a block.
Read This First
概述
New API 已支持 OIDC 登录(网页端),但 HTTP API(
/api/*)只认自家凭证(系统访问令牌或 session cookie)。在自部署且已有统一身份源(IdP)的场景下,服务端集成手里持有该用户的有效 OIDC 令牌,却无法以此用户身份调用 API。实测(授权端点、JWKS、userinfo 均已验证可用):
建议(任一形态均可解决)
/api/*直接认可 OIDC 令牌:增加设置项(默认关闭)配置 IdP 的 issuer/JWKS;开启后校验Authorization: Bearer <oidc-token>,按oidc_id映射到本地用户(OIDC 登录本来就在维护这个映射),以该用户身份鉴权。可附带 scope 限制。POST /api/oauth/exchange,校验 OIDC 令牌后签发该用户的 session/access token——不改动现有鉴权中间件,给集成方一个单一桥接点。使用场景
自部署 + 统一 IdP(Casdoor/Keycloak 等)的场景:桌面端、嵌入式客户端通过 IdP 完成用户认证后,中间层服务需要以用户个人身份访问 API——余额展示(
/api/user/self)、个人日志(/api/log/self)等,实现按用户审计;而不是共享一个管理员令牌。目前的替代方案只有“每个用户手动生成并登记系统访问令牌”或“持有管理员凭据模拟登录”,这两种都不符合以 IdP 为中心的认证流程。Your current newapi version
rc-38
Submission Checks
latestorunknown) and confirm this feature request is for an unmodified, supported version from this repository.Feature Description
/api/*直接认可 OIDC 令牌:增加设置项(默认关闭)配置 IdP 的 issuer/JWKS;开启后校验Authorization: Bearer <oidc-token>,按oidc_id映射到本地用户(OIDC 登录本来就在维护这个映射),以该用户身份鉴权。可附带 scope 限制。POST /api/oauth/exchange,校验 OIDC 令牌后签发该用户的 session/access token——不改动现有鉴权中间件,给集成方一个单一桥接点。Use Case
自部署 + 统一 IdP(Casdoor/Keycloak 等)的场景:桌面端、嵌入式客户端通过 IdP 完成用户认证后,中间层服务需要以用户个人身份访问 API——余额展示(
/api/user/self)、个人日志(/api/log/self)等,实现按用户审计;而不是共享一个管理员令牌。目前的替代方案只有“每个用户手动生成并登记系统访问令牌”或“持有管理员凭据模拟登录”,这两种都不符合以 IdP 为中心的认证流程。