headscale/docs/ref
Ryan Malloy da2878e8fb docs/oidc: warn about Authentik's built-in groups scope duplicating claims
Authentik 2025.8 ships a default 'groups' scope that emits the user's
ak_groups as the 'groups' claim automatically. Adding a custom scope
mapping with the same scope_name causes Authentik to concatenate
both emitters' output, producing duplicated group names in the
users.groups column.

Document the symptom and the fix, plus a sibling note that Keycloak
needs the opposite (explicit mapper required to emit anything).
2026-06-06 10:31:23 -06:00
..
integration docs: document trusted_proxies config option 2026-05-18 17:17:55 +02:00
api.md Update docs for auth-id changes 2026-03-01 13:38:22 +01:00
configuration.md Reformat docs with mdformat 2026-03-01 09:24:52 +01:00
debug.md Refresh docs for Grants 2026-05-12 14:12:29 +02:00
derp.md Remove redundant prefix 2026-05-12 14:12:29 +02:00
dns.md Remove redundant prefix 2026-05-12 14:12:29 +02:00
oidc.md docs/oidc: warn about Authentik's built-in groups scope duplicating claims 2026-06-06 10:31:23 -06:00
policy.md Add docs for policy-wide options and node attributes 2026-05-18 17:21:58 +02:00
registration.md Rewrite ACL docs as policy 2026-05-12 14:12:29 +02:00
routes.md Refresh docs for Grants 2026-05-12 14:12:29 +02:00
tags.md Update links to Tailscale documentation 2026-04-18 09:33:41 +02:00
tls.md Reformat docs with mdformat 2026-03-01 09:24:52 +01:00