# Gitea user authentication with external users still needs local password

**URL:** <https://forum.gitea.com/t/gitea-user-authentication-with-external-users-still-needs-local-password/9423>\
**Category:** Install/Maintain/Configure\
**Created:** [July 10, 2024, 10:53am UTC](https://forum.gitea.com/t/gitea-user-authentication-with-external-users-still-needs-local-password/9423 "2024-07-10T10:53:36Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![OCram85](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.gitea.com/ocram85/32/4947_2.png) [@OCram85](https://forum.gitea.com/u/OCram85)\
**Post date:** [July 10, 2024, 10:53am UTC](https://forum.gitea.com/t/gitea-user-authentication-with-external-users-still-needs-local-password/9423/1 "2024-07-10T10:53:36Z")

</div>

Hey folks, I recently switched to Authentik as IDPin front of our Gitea instances.

So I also configured Gitea to only accept external oauth2 accounts from Authentik which gets the users and groups from connected Active Directories.

I just noticed, that the users still need to set an local Gitea password in their profile to access their repos.

Is there a way to avoid this?

btw. - I already tested the config keys

- `REQUIRE_EXTERNAL_REGISTRATION_PASSWORD`: Expected password prompt after redirected oauth login but user still lands on his dashboard after registration.
- `ACCOUNT_LINKING=disabled` → disables wrong account linking if underling user directory doesn’t handle email field as unique.

* * *

Used gitea config:

```yaml
environment:
  GITEA __actions__ DEFAULT_ACTIONS_URL: "https://foobar.com"
  GITEA __actions__ ENABLED: "true"
  GITEA __admin__ DEFAULT_EMAIL_NOTIFICATIONS: "enabled"
  GITEA __admin__ DISABLE_REGULAR_ORG_CREATION: "true"
  GITEA __database__ DB_TYPE: "postgres"
  GITEA __database__ HOST: "${$DB_HOST}"
  GITEA __database__ NAME: "${DB_NAME}"
  GITEA __database__ PASSWD: "${$DB_PASSWD}"
  GITEA __database__ USER: "${DB_USER}"
  GITEA __default__ APP_NAME: "My Gitea"
  GITEA __mailer__ ENABLED: "true"
  GITEA __mailer__ PROTOCOL: "smtp"
  GITEA __mailer__ SMTP_ADDR: "mx.foobar.com"
  GITEA __mailer__ SMTP_PORT: "25"
  GITEA __migrations__ ALLOW_LOCALNETWORKS: "true"
  GITEA __oauth2_client__ ACCOUNT_LINKING: "disabled"
  GITEA __openid__ ENABLE_OPENID_SIGNIN: "true"
  GITEA __openid__ ENABLE_OPENID_SIGNUP: "true"
  GITEA __openid__ WHITELISTED_URIS: "auth.foobar.com"
  GITEA __server__ DISABLE_SSH: "true"
  GITEA __server__ ROOT_URL: "https://code.foobar.com"
  GITEA __service__ ALLOW_ONLY_EXTERNAL_REGISTRATION: "true"
  GITEA __service__ DISABLE_REGISTRATION: "false"
  GITEA __service__ EMAIL_DOMAIN_ALLOWLIST: "foobar.com"
  GITEA __service__ ENABLE_NOTIFY_MAIL: "true"
  GITEA __service__ NO_REPLY_ADDRESS: "noreply@code.foobar.com"
  GITEA __service__ REGISTER_EMAIL_CONFIRM: "true"
  GITEA __service__ REGISTER_MANUAL_CONFIRM: "false"
  GITEA __service__ REQUIRE_EXTERNAL_REGISTRATION_PASSWORD: "true"
  GITEA __service__ REQUIRE_SIGNIN_VIEW: "true"
  GITEA __service__ SHOW_REGISTRATION_BUTTON: "false"
  GITEA __webhook__ ALLOWED_HOST_LIST: "*.foobar.com"
  USER_GID: "1000"
  USER_UID: "1000"

```

---

<div class="post-metadata">

**Author:** ![micaelsilva](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.gitea.com/micaelsilva/32/7013_2.png) [@micaelsilva](https://forum.gitea.com/u/micaelsilva)\
**Post date:** [July 23, 2025, 9:51pm UTC](https://forum.gitea.com/t/gitea-user-authentication-with-external-users-still-needs-local-password/9423/2 "2025-07-23T21:51:48Z")

</div>

You need the option GITEA\_\_oauth2\_client\_\_ENABLE\_AUTO\_REGISTRATION to make Gitea automatically create users. But it only works if the username doesnt exists locally yet, in that case it will ask for the password

You can manually link those users changing the authentication source on the admin interface and using their user UUID in Authentication Sign-In Name, at least that is the field that Keycloak uses.
