sources

Kerberos Source Viewset

get/sources/kerberos/{slug}/

Path parameters

slugstring required

Internal source name, used in URLs.

Response

pkstring uuid required
namestring required

Source's display Name.

slugstring required

Internal source name, used in URLs.

enabledboolean
promotedboolean

When enabled, this source will be displayed as a prominent button on the login page, instead of a small icon.

authentication_flowstring uuid nullable

Flow to use when authenticating existing users.

enrollment_flowstring uuid nullable

Flow to use when enrolling new users.

user_property_mappingsstring[]
group_property_mappingsstring[]
componentstring required

Get object component so that we know how to edit the object

verbose_namestring required

Return object's verbose_name

verbose_name_pluralstring required

Return object's plural verbose_name

meta_model_namestring required

Return internal model name

policy_engine_mode'all' | 'any'
user_matching_mode'identifier' | 'email_link' | 'email_deny' | 'username_link' | 'username_deny'
managedstring nullable required

Objects that are managed by authentik. These objects are created and updated automatically. This flag only indicates that an object can be overwritten by migrations. You can still modify the objects via the API, but expect changes to be overwritten in a later update.

user_path_templatestring
iconstring
icon_urlstring required
group_matching_mode'identifier' | 'name_link' | 'name_deny'
realmstring required

Kerberos realm

krb5_confstring

Custom krb5.conf to use. Uses the system one by default

kadmin_type'MIT' | 'Heimdal'
sync_usersboolean

Sync users from Kerberos into authentik

sync_users_passwordboolean

When a user changes their password, sync it back to Kerberos

sync_principalstring

Principal to authenticate to kadmin for sync.

sync_ccachestring

Credentials cache to authenticate to kadmin for sync. Must be in the form TYPE:residual

connectivityobject nullable required

Get cached source connectivity

spnego_server_namestring

Force the use of a specific server name for SPNEGO. Must be in the form HTTP@hostname

spnego_ccachestring

Credential cache to use for SPNEGO in form type:residual

password_login_update_internal_passwordboolean

If enabled, the authentik-stored password will be updated upon login with the Kerberos password backend

sync_outgoing_trigger_mode'none' | 'immediate' | 'deferred_end'

Changes

No recorded changes to this endpoint across all 1 revision of this API.