A production-ready Duende IdentityServer for testing purposes only instance with HTTPS support, pre-configured clients, and flexible authentication options including X.509 certificates and JSON Web Keys.
Pull and run the image:
docker pull jtenorio/duende-idp:latest
docker run -d -p 5000:5000 -p 5001:5001 --name duende-idp duende-idp:latest
Access the IdentityServer:
| Username | Password | Role | |
|---|---|---|---|
| alice | alice | - | [email protected] |
| bob | bob | - | [email protected] |
| admin | admin | admin | [email protected] |
| dseldon | mycomplexPassword33#45% | admin | [email protected] |
ClientId: interactive
ClientSecret: secret
Grant Type: Authorization Code + PKCE
Redirect URI: https://localhost:5444/signin-oidc
Scopes: openid, profile, email, api1
ClientId: m2m
ClientSecret: secret
Grant Type: Client Credentials
Scopes: api1, api2
ClientId: spa
Grant Type: Authorization Code + PKCE
Redirect URI: http://localhost:4200/callback
CORS Origin: http://localhost:4200
Scopes: openid, profile, email, api1
ClientId: test.client
ClientSecret: test.secret
Grant Type: Resource Owner Password
Scopes: openid, profile, email, api1, api2
The image automatically generates a self-signed certificate during build:
Mount your certificate into the container:
docker run -d \
-p 5000:5000 -p 5001:5001 \
-v /path/to/your/certificate.pfx:/app/certificate.pfx \
-e ASPNETCORE_Kestrel__Certificates__Default__Password=YourPassword \
--name duende-idp \
duende-idp:latest
| Variable | Default | Description |
|---|---|---|
ASPNETCORE_ENVIRONMENT | Production | Environment (Development/Production) |
ASPNETCORE_URLS | https://+:5001;http://+:5000 | URLs to listen on |
ASPNETCORE_Kestrel__Certificates__Default__Path | /app/certificate.pfx | Certificate path |
ASPNETCORE_Kestrel__Certificates__Default__Password | (empty) | Certificate password |
Mount a custom appsettings.json file:
docker run -d \
-p 5000:5000 -p 5001:5001 \
-v /path/to/your/appsettings.json:/app/appsettings.json \
--name duende-idp \
duende-idp:latest
This image supports three types of client secrets for enhanced security:
{
"ClientId": "my.client",
"ClientSecrets": ["my-secret"]
}
{
"ClientId": "my.client",
"ClientSecretsTyped": [
{
"Type": "X509CertificateBase64",
"Value": "MIID...base64cert...",
"Description": "Client certificate"
}
]
}
{
"ClientId": "my.client",
"ClientSecretsTyped": [
{
"Type": "JsonWebKey",
"Value": "{\"e\":\"AQAB\",\"kty\":\"RSA\",\"n\":\"...\"}",
"Description": "JWK for authentication"
}
]
}
{
"ClientId": "my.client",
"ClientSecretsTyped": [
{
"Type": "SharedSecret",
"Value": "current-secret",
"Description": "Current secret"
},
{
"Type": "SharedSecret",
"Value": "old-secret",
"Description": "Previous secret",
"Expiration": "2025-12-31T23:59:59Z"
}
]
}
Pre-configured API scopes available for token requests:
api1 - My APIapi2 - Another APIscope1 - Custom Scope 1scope2 - Custom Scope 2Standard OpenID Connect identity resources:
openid - Required for OpenID Connectprofile - User profile informationemail - Email addressphone - Phone numberaddress - Physical address# Start the server
docker run -d -p 5000:5000 -p 5001:5001 --name duende-idp duende-idp:latest
# Your application connects to https://localhost:5001
# Use pre-configured clients for testing OAuth/OIDC flows
services:
identityserver:
image: duende-idp:latest
ports:
- "5001:5001"
environment:
- ASPNETCORE_ENVIRONMENT=Development
# Start container before tests
docker run -d -p 5001:5001 --name test-idp duende-idp:latest
# Run your integration tests
dotnet test
# Stop container after tests
docker stop test-idp && docker rm test-idp
Create a docker-compose.yml:
version: '3.8'
services:
duende-idp:
image: duende-idp:latest
container_name: duende-identityserver
ports:
- "5000:5000"
- "5001:5001"
environment:
- ASPNETCORE_ENVIRONMENT=Development
- ASPNETCORE_URLS=https://+:5001;http://+:5000
restart: unless-stopped
Start with:
docker-compose up -d
curl -k https://localhost:5001/.well-known/openid-configuration
curl -k -X POST https://localhost:5001/connect/token \
-H "Content-Type: application/x-www-form-urlencoded" \
-d "client_id=m2m" \
-d "client_secret=secret" \
-d "grant_type=client_credentials" \
-d "scope=api1"
curl -k -X POST https://localhost:5001/connect/token \
-H "Content-Type: application/x-www-form-urlencoded" \
-d "client_id=test.client" \
-d "client_secret=test.secret" \
-d "grant_type=password" \
-d "username=alice" \
-d "password=alice" \
-d "scope=openid profile api1"
When accessing via HTTPS, browsers will show a security warning. This is expected with self-signed certificates:
docker logs duende-idp
docker exec -it duende-idp /bin/bash
Change the host port mapping:
docker run -d -p 8080:5000 -p 8443:5001 --name duende-idp duende-idp:latest
This image is optimized for development and testing. For production:
This Docker image uses Duende IdentityServer which requires a license for production use. The software includes:
Visit Duende Software for licensing information.
For issues, questions, or contributions:
latest - Latest stable build with .NET 9.0Quick Links:
docker pull duende-idp:latestdocker run -d -p 5001:5001 duende-idp:latesthttps://localhost:5001/.well-known/openid-configurationContent type
Image
Digest
sha256:a06735ce7…
Size
105.2 MB
Last updated
11 months ago
docker pull jtenorio/duende-idp