Dex acts as a bridge between an application and the organization's existing login systems. The application speaks OpenID Connect to Dex; Dex uses a connector to authenticate the user with a provider such as a directory or another identity service. It is useful when several applications need a consistent login interface despite different upstream providers. Login establishes identity, while each application must still decide what the signed-in user is allowed to do.
Deployment and operating notes
Dex remains an OpenID Connect identity service that connects applications to upstream identity providers. Its project-owned Helm chart and current connector documentation supersede the archived stable package and the old table of alpha, beta and claim support. Connector behavior, especially groups and refresh tokens, must be checked for the chosen connector and version.
Inventory issuer URL, client IDs, redirect URIs, signing-key storage and upstream provider configuration before migration. Preserve persistent storage where it contains keys or sessions, and avoid changing the issuer URL casually because relying applications validate it. Test authorization-code login, token refresh, group changes, denied users and expiry with the actual client applications. A memory-backed demonstration setup is not evidence of durable multi-replica operation. Keep TLS and cookie behavior consistent through the ingress path, and restrict administrative interfaces. A successful authentication response does not prove the application applies the intended authorization policy; verify a low-privilege identity before switching all clients.
Historical upstream link check · 2026-10-09
The recorded upstream address responded successfully (HTTP 200) on 2026-10-09. GitHub confirms that helm/charts is archived: this is a historical chart distribution, not evidence that the application itself is retired. Link availability does not certify the historical installation instructions or current security support.
Website availability is separate from project, chart and image support. Use the current guidance and primary sources on this page to assess the distribution.
Historical Kubedex content
Original publication: 2018-10-07T08:28:42+00:00. Preserved for context. Commands, versions, prices and results below reflect the original research.
Dex is an identity service that uses OpenID Connect to drive authentication for other apps.
Dex acts as a portal to other identity providers through “connectors.” This lets dex defer authentication to LDAP servers, SAML providers, or established identity providers like GitHub, Google, and Active Directory. Clients write their authentication logic once to talk to dex, then dex handles the protocols for a given backend.
Dex implements the following connectors:
| Name | supports refresh tokens | supports groups claim | status | notes |
|---|---|---|---|---|
| LDAP | yes | yes | stable | |
| GitHub | yes | yes | stable | |
| SAML 2.0 | no | yes | stable | |
| GitLab | yes | yes | beta | |
| OpenID Connect | yes | no (#1065) | beta | Includes Google, Salesforce, Azure, etc. |
| yes | no | beta | ||
| Microsoft | yes | yes | beta | |
| AuthProxy | no | no | alpha | Authentication proxies such as Apache2 mod_auth, etc. |
The post Dex appeared first on kubedex.com.
Sources & further reading
Spotted something that needs another look?
Help improve this page →