Authentication
Camunda Hub authenticates users with OpenID Connect (OIDC).
Authentication and user management
Camunda Hub authenticates users with its own properties (see Identity / Keycloak), while Management Identity keeps managing users and their access. For how the responsibilities are split, see management and modeling component authentication.
Management Identity is still required for Camunda Hub in 8.10. For more information, see manage access and permissions.
Configure OIDC authentication
Configure Camunda Hub's OIDC authentication with the properties documented under Identity / Keycloak, not with the Orchestration Cluster's camunda.security.authentication.oidc.* settings. For the one exception, the username claim, see the same section.
Use a different OIDC provider than Keycloak
By default, Camunda Hub uses the built-in Keycloak instance as its identity provider. To use a different OIDC provider, follow the steps in the OIDC connection guide.