Red Hat signs users in through Red Hat SSO, the OpenID Connect realm at `sso.redhat.com`.

## Copy the redirect URI

In the [Authdog console](https://console.authdog.com), select the project and environment, open **Authentication > Providers**, find **Red Hat**, and click **Enable**. Copy the redirect URI shown in the form:

```url
https://identity.authdog.com/api/v1/callback/<connectionId>
```

## Create the application

1. Register an OAuth client for the Red Hat SSO realm `redhat-external`.
2. Set the redirect URI to the value copied from Authdog.
3. Request the scopes `openid`, `email`, and `profile`.
4. Copy the **client ID** and **client secret**.

## Configure Authdog

| Field | Value |
| --- | --- |
| **Client ID** | The Red Hat client ID |
| **Client Secret** | The Red Hat client secret |

Save, then toggle the connection **active**.

## What Red Hat returns

Authdog uses the authorization-code flow against `https://sso.redhat.com/auth/realms/redhat-external/protocol/openid-connect/auth` and reads the profile from the realm userinfo endpoint.

The userinfo response includes the subject and, when the `email` scope is granted, an email address.

## Test it

1. Open your environment's hosted sign-in page, or link to `https://identity.authdog.com/api/v1/signin/<connectionId>`.
2. Select the Red Hat button and complete the flow.
3. Confirm the user appears under **Users** in the console with a Red Hat identity linked.

## Troubleshooting

| Symptom | Cause |
| --- | --- |
| `redirect_uri_mismatch` | The callback registered on the client differs from Authdog's redirect URI |
| No email on the user | The client was not granted the `email` scope |
| Works in one environment only | Each environment has its own `connectionId`, and so its own redirect URI |

## Related

| Read | To learn how to |
| --- | --- |
| [Connectors](/docs/connectors) | Set up any other social provider |
| [Enterprise SSO](/docs/sso) | Connect a SAML or OpenID Connect workforce IdP |
