PHPackages                             sizestation/roundcube-oidc-suite - PHPackages - PHPackages  [Skip to content](#main-content)[PHPackages](/)[Directory](/)[Categories](/categories)[Trending](/trending)[Leaderboard](/leaderboard)[Changelog](/changelog)[Analyze](/analyze)[Collections](/collections)[Log in](/login)[Sign up](/register)

1. [Directory](/)
2. /
3. sizestation/roundcube-oidc-suite

ActiveRoundcube-plugin

sizestation/roundcube-oidc-suite
================================

Single-package Authentik OIDC and OpenBao-managed multi-account support for Roundcube

v1.0.0-rc.20(1mo ago)011↓66.7%AGPL-3.0-or-laterPHPPHP &gt;=8.2CI passing

Since Jul 16Pushed 1mo agoCompare

[ Source](https://github.com/SizeStation/roundcube-custom-oidc)[ Packagist](https://packagist.org/packages/sizestation/roundcube-oidc-suite)[ RSS](/packages/sizestation-roundcube-oidc-suite/feed)WikiDiscussions main Synced 1w ago

READMEChangelogDependencies (8)Versions (21)Used By (0)

SizeStation Roundcube OIDC
==========================

[](#sizestation-roundcube-oidc)

This single Composer package adds Authentik sign-in and OpenBao-managed Purelymail credentials to Roundcube 1.7. It extends the upstream `ident_switch` 5.0.4 plugin instead of replacing its multi-account switching.

The browser authenticates the person with OIDC. Roundcube then retrieves the assigned mailbox app password from OpenBao and performs ordinary TLS IMAP/SMTP authentication; Authentik tokens are never sent to Purelymail.

Documentation
-------------

[](#documentation)

- [Architecture](docs/architecture.md)
- [Production deployment](docs/deployment.md)
- [Authentik configuration](docs/authentik.md)
- [Provisioning and operations](docs/operations.md)
- [Security, risks, and limitations](docs/security.md)
- [`ident_switch` fork changes](docs/ident-switch-upstream-diff.md)
- [Verification report](docs/verification.md)

Start with `docs/deployment.md`. Example assets in `deployment/` contain placeholders only and must not be deployed before replacing them.

Development verification
------------------------

[](#development-verification)

```
composer install
composer test
composer lint
```

Production uses the official Roundcube image with `ROUNDCUBEMAIL_COMPOSER_PLUGINS=sizestation/roundcube-oidc-suite:VERSION`. The package is a standard `roundcube-plugin`; Roundcube's Composer installer places it directly in `plugins/roundcube_oidc_suite`, creates its config stub, and invokes its supported install/update hook. On a configured Roundcube that hook applies the database schema immediately. In the official Docker image it registers the migration as a built-in post-setup task, because that image creates its database configuration after Composer runs. The migration still finishes before Apache starts. The plugin reads its custom environment variables internally. No mounted PHP config, custom image, custom service command, or manual migration step is required.

Mailbox administration on a Docker host is exposed through the bundled `bin/roundcube-oidc-admin` launcher. It provides short commands for provisioning users, adding mailboxes, rotating credentials, and enabling, disabling, or removing assignments. It accepts OpenBao AppRole credentials, authenticates inside its one-shot container, and keeps all provisioning credentials out of the web container.

Licence and source availability
-------------------------------

[](#licence-and-source-availability)

The SizeStation distribution is licensed under AGPL-3.0-or-later. The retained upstream plugin notices and complete GNU AGPL text are in `plugins/ident_switch/LICENSE`. Anyone interacting with a modified deployed version over a network must be offered the corresponding source for that exact package release. Publish the immutable Git commit/tag and source archive; see `SOURCE-AVAILABILITY.md`.

###  Health Score

38

—

LowBetter than 82% of packages

Maintenance91

Actively maintained with recent releases

Popularity5

Limited adoption so far

Community10

Small or concentrated contributor base

Maturity41

Maturing project, gaining track record

 Bus Factor1

Top contributor holds 50.4% of commits — single point of failure

How is this calculated?**Maintenance (25%)** — Last commit recency, latest release date, and issue-to-star ratio. Uses a 2-year decay window.

**Popularity (30%)** — Total and monthly downloads, GitHub stars, and forks. Logarithmic scaling prevents top-heavy scores.

**Community (15%)** — Contributors, dependents, forks, watchers, and maintainers. Measures real ecosystem engagement.

**Maturity (30%)** — Project age, version count, PHP version support, and release stability.

###  Release Activity

Cadence

Every ~0 days

Total

20

Last Release

44d ago

### Community

Maintainers

![](https://avatars.githubusercontent.com/u/41944315?v=4)[Sky](/maintainers/SkyDev125)[@SkyDev125](https://github.com/SkyDev125)

---

Top Contributors

[![BoresXP](https://avatars.githubusercontent.com/u/18707586?v=4)](https://github.com/BoresXP "BoresXP (133 commits)")[![SkyDev125](https://avatars.githubusercontent.com/u/41944315?v=4)](https://github.com/SkyDev125 "SkyDev125 (80 commits)")[![loxK](https://avatars.githubusercontent.com/u/136687?v=4)](https://github.com/loxK "loxK (45 commits)")[![lvogt](https://avatars.githubusercontent.com/u/36930594?v=4)](https://github.com/lvogt "lvogt (6 commits)")

###  Code Quality

TestsPHPUnit

Code StylePHP\_CodeSniffer

### Embed Badge

![Health badge](/badges/sizestation-roundcube-oidc-suite/health.svg)

```
[![Health](https://phpackages.com/badges/sizestation-roundcube-oidc-suite/health.svg)](https://phpackages.com/packages/sizestation-roundcube-oidc-suite)
```

###  Alternatives

[laravel/socialite

Laravel wrapper around OAuth 1 &amp; OAuth 2 libraries.

5.7k118.2M1.0k](/packages/laravel-socialite)[typo3/cms

TYPO3 CMS is a free open source Content Management Framework initially created by Kasper Skaarhoj and licensed under GNU/GPL.

1.2k1.9M122](/packages/typo3-cms)[civicrm/civicrm-core

Open source constituent relationship management for non-profits, NGOs and advocacy organizations.

769306.5k56](/packages/civicrm-civicrm-core)[xeroapi/xero-php-oauth2

Xero official PHP SDK for oAuth2 generated with OpenAPI spec 3

1075.1M21](/packages/xeroapi-xero-php-oauth2)[typo3/cms-core

TYPO3 CMS Core

3714.0M5.9k](/packages/typo3-cms-core)[toteph42/identity_switch

This plugin allows users to switch between different identities (and check for new mails) in a single Roundcube session.

251.7k](/packages/toteph42-identity-switch)

PHPackages © 2026

[Directory](/)[Categories](/categories)[Trending](/trending)[Changelog](/changelog)[Analyze](/analyze)
