# How is GitLab SSO configured in GitLab Mattermost?

**URL:** <https://forum.mattermost.com/t/how-is-gitlab-sso-configured-in-gitlab-mattermost/147>\
**Category:** Troubleshooting\
**Created:** [August 26, 2015, 12:57am UTC](https://forum.mattermost.com/t/how-is-gitlab-sso-configured-in-gitlab-mattermost/147 "2015-08-26T00:57:55Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![it33](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mattermost.com/it33/32/3_2.png) [@it33](https://forum.mattermost.com/u/it33)\
**Post date:** [August 26, 2015, 12:57am UTC](https://forum.mattermost.com/t/how-is-gitlab-sso-configured-in-gitlab-mattermost/147/1 "2015-08-26T00:57:55Z")

</div>

GitLab SSO for Mattermost alpha (v0.6.0) focused on sign-up and login of user accounts, and was not available for restricting or facilitating team creation (the first screen of the Mattermost experience).

Based on feedback from the GitLab community the following features are being developed for the September 4 release of Mattermost v0.7.0, and v0.7.0-rc1 should be available August 31.

- [PL-2 - Add option to require GitLab SSO for team creation](https://mattermost.atlassian.net/browse/PL-2)

 ![](https://us1.discourse-cdn.com/flex020/uploads/mattermost/original/1X/4b577619b64ddcf82d291770c1a3b91e38c9f3fa.png) 

- [PL-3 - Add option to restrict team creation to emails from a specific domain when email verification is turned on](https://mattermost.atlassian.net/browse/PL-3)

- [PL-1 - Add option to disable creation of new teams](https://mattermost.atlassian.net/browse/PL-1)

The links in the list above lead to tickets in the new Mattermost issue tracker where you can monitor the progress of these changes.

---

<div class="post-metadata">

**Author:** ![cifvts](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mattermost.com/cifvts/32/20_2.png) [@cifvts](https://forum.mattermost.com/u/cifvts)\
**Post date:** [August 26, 2015, 9:22am UTC](https://forum.mattermost.com/t/how-is-gitlab-sso-configured-in-gitlab-mattermost/147/2 "2015-08-26T09:22:25Z")

</div>

Will this be possible also with a standalone installation of Mattermost? I will like something that allow users of GitLab to access Team in Mattermost and have a control of that

---

<div class="post-metadata">

**Author:** ![it33](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mattermost.com/it33/32/3_2.png) [@it33](https://forum.mattermost.com/u/it33)\
**Post date:** [August 26, 2015, 2:43pm UTC](https://forum.mattermost.com/t/how-is-gitlab-sso-configured-in-gitlab-mattermost/147/3 "2015-08-26T14:43:20Z")

</div>

hi @cifvts, yes, these features will be available in the standalone version of Mattermost as well,

---

<div class="post-metadata">

**Author:** ![jwilander](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mattermost.com/jwilander/32/8440_2.png) [@jwilander](https://forum.mattermost.com/u/jwilander)\
**Post date:** [August 31, 2015, 2:33pm UTC](https://forum.mattermost.com/t/how-is-gitlab-sso-configured-in-gitlab-mattermost/147/4 "2015-08-31T14:33:34Z")

</div>

The following steps can be used to configure Mattermost to use GitLab as a single-sign-on (SSO) service in v0.7.0.

1. Login to your GitLab account and go to the Applications section either in Profile Settings or Admin Area.
2. Add a new application called “Mattermost” with the following as Redirect URIs:

- `<your-mattermost-url>/login/gitlab/complete` (example: [http://localhost:8065/login/gitlab/complete](http://localhost:8065/login/gitlab/complete))
- `<your-mattermost-url>/signup/gitlab/complete`

1. Submit the application and copy the given _Id_ and _Secret_ into the appropriate _SSOSettings_ fields in config/config.json

2. Also in config/config.json, set _Allow_ to `true` for the _gitlab_ section, leave _Scope_ blank and use the following for the endpoints:

- _AuthEndpoint_: `<your-gitlab-url>/oauth/authorize` (example [http://localhost:3000/oauth/authorize](http://localhost:3000/oauth/authorize))
- _TokenEndpoint_: `<your-gitlab-url>/oauth/token`
- _UserApiEndpoint_: `<your-gitlab-url>/api/v3/user`

1. (Optional) If you would like to force all users to sign-up with GitLab only, in the _ServiceSettings_ section of config/config.json please set _AllowEmailSignUp_ to `false`.

2. Restart your Mattermost server to see the changes take effect.
