---
title: Charmhub | Deploy Kratos External Idp Integrator using Charmhub - The Open
  Operator Collection
description: Deploy the latest version of Kratos External Idp Integrator on any cloud.
url: https://charmhub.io/kratos-external-idp-integrator/configurations
---

# Kratos External Idp Integrator

[Identity Charmers](https://charmhub.io/publisher/identity-charmers "View all packages from Identity Charmers")

* [Identity Charmers](https://charmhub.io/publisher/identity-charmers "View all packages from Identity Charmers")

Platform:

22.04

stable 299

```
juju deploy kratos-external-idp-integrator
```

[Learn to deploy on juju >](https://juju.is/docs/juju/manage-applications)

* [apple\_private\_key](https://charmhub.io/kratos-external-idp-integrator/configurations#apple_private_key)
* [apple\_private\_key\_id](https://charmhub.io/kratos-external-idp-integrator/configurations#apple_private_key_id)
* [apple\_team\_id](https://charmhub.io/kratos-external-idp-integrator/configurations#apple_team_id)
* [client\_id](https://charmhub.io/kratos-external-idp-integrator/configurations#client_id)
* [client\_secret](https://charmhub.io/kratos-external-idp-integrator/configurations#client_secret)
* [enabled](https://charmhub.io/kratos-external-idp-integrator/configurations#enabled)
* [issuer\_url](https://charmhub.io/kratos-external-idp-integrator/configurations#issuer_url)
* [jsonnet\_mapper](https://charmhub.io/kratos-external-idp-integrator/configurations#jsonnet_mapper)
* [label](https://charmhub.io/kratos-external-idp-integrator/configurations#label)
* [microsoft\_tenant\_id](https://charmhub.io/kratos-external-idp-integrator/configurations#microsoft_tenant_id)
* [provider](https://charmhub.io/kratos-external-idp-integrator/configurations#provider)
* [provider\_id](https://charmhub.io/kratos-external-idp-integrator/configurations#provider_id)
* [scope](https://charmhub.io/kratos-external-idp-integrator/configurations#scope)
* [secret\_backend](https://charmhub.io/kratos-external-idp-integrator/configurations#secret_backend)

[Learn about configurations >](https://juju.is/docs/juju/configuration#heading--application-configuration)

* apple\_private\_key | string

  The private key downloaded from Apple. To be used only with Apple providers.
* apple\_private\_key\_id | string

  The private key identifier generated by Apple. To be used only with Apple providers.
* apple\_team\_id | string

  The Team ID provided by Apple. To be used only with Apple providers.
* client\_id | string

  The registered client\_id
* client\_secret | string

  The registered client\_secret
* enabled | boolean

  Default: True

  Controls whether the provider is enabled.
* issuer\_url | string

  The issuer\_url, this value is only used when provider is "generic" or "auth0"
* jsonnet\_mapper | string

  The jsonnet mapper that will be used for mapping the external idp claims to kratos attributes.
  For example:

  local claims = {
  email\_verified: false,
  } + std.extVar('claims');

  {
  identity: {
  traits: {
  [if 'email' in claims && claims.email\_verified then 'email' else null]: claims.email,
  [if 'name' in claims then 'name' else null]: claims.name,
  [if 'given\_name' in claims then 'given\_name' else null]: claims.given\_name,
  [if 'family\_name' in claims then 'family\_name' else null]: claims.family\_name,
  },
  },
  }

  For more info see https://www.ory.sh/docs/kratos/reference/jsonnet.
* label | string

  The text that will be shown to the user when asked to choose a provider, defaults to the provider type
* microsoft\_tenant\_id | string

  The Microsoft tenant\_id. To be used only with Microsoft providers.
* provider | string

  Default: generic

  The provider name, must be one of the following:
  ["generic", "google", "facebook", "microsoft", "github",
  "apple", "gitlab", "auth0", "slack", "spotify", "discord",
  "twitch", "netid", "yandex", "vk", "dingtalk"].
  Defaults to "generic"
* provider\_id | string

  The provider's ID to be used in Kratos. The redirect\_uri is generated based on this.
  You must not have 2 providers with the same ID registered in Kratos.
* scope | string

  Space separated list of allowed scopes for the provider.
* secret\_backend | string

  Default: relation

  The backend to use for passing sensitive information to Kratos.
