OceanBase logo

OceanBase

A unified distributed database ready for your transactional, analytical, and AI workloads.

DEPLOY YOUR WAY

OceanBase Cloud

The best way to deploy and scale OceanBase

OceanBase Enterprise

Run and manage OceanBase on your infra

TRY OPEN SOURCE

OceanBase Community Edition

The free, open-source distributed database

OceanBase seekdb

Open source AI native search database

Customer Stories

Real-world success stories from enterprises across diverse industries.

View All
BY USE CASES

Mission-Critical Transactions

Global & Multicloud Application

Elastic Scaling for Peak Traffic

Real-time Analytics

Active Geo-redundancy

Database Consolidation

Resources

Comprehensive knowledge hub for OceanBase.

Blog

Live Demos

Training & Certification

Documentation

Official technical guides, tutorials, API references, and manuals for all OceanBase products.

View All
PRODUCTS

OceanBase Cloud

OceanBase Database

Tools

Connectors and Middleware

QUICK START

OceanBase Cloud

OceanBase Database

BEST PRACTICES

Practical guides for utilizing OceanBase more effectively and conveniently

Company

Learn more about OceanBase – our company, partnerships, and trust and security initiatives.

About OceanBase

Partner

Trust Center

Contact Us

International - English
中国站 - 简体中文
日本 - 日本語
Sign In
Start on Cloud

A unified distributed database ready for your transactional, analytical, and AI workloads.

DEPLOY YOUR WAY

OceanBase Cloud

The best way to deploy and scale OceanBase

OceanBase Enterprise

Run and manage OceanBase on your infra

TRY OPEN SOURCE

OceanBase Community Edition

The free, open-source distributed database

OceanBase seekdb

Open source AI native search database

Customer Stories

Real-world success stories from enterprises across diverse industries.

View All
BY USE CASES

Mission-Critical Transactions

Global & Multicloud Application

Elastic Scaling for Peak Traffic

Real-time Analytics

Active Geo-redundancy

Database Consolidation

Comprehensive knowledge hub for OceanBase.

Blog

Live Demos

Training & Certification

Documentation

Official technical guides, tutorials, API references, and manuals for all OceanBase products.

View All
PRODUCTS
OceanBase CloudOceanBase Database
ToolsConnectors and Middleware
QUICK START
OceanBase CloudOceanBase Database
BEST PRACTICES

Practical guides for utilizing OceanBase more effectively and conveniently

Learn more about OceanBase – our company, partnerships, and trust and security initiatives.

About OceanBase

Partner

Trust Center

Contact Us

Start on Cloud
编组
All Products
    • Databases
    • iconOceanBase Database
    • iconOceanBase Cloud
    • iconOceanBase Tugraph
    • iconInteractive Tutorials
    • iconOceanBase Best Practices
    • Tools
    • iconOceanBase Cloud Platform
    • iconOceanBase Migration Service
    • iconOceanBase Developer Center
    • iconOceanBase Migration Assessment
    • iconOceanBase Admin Tool
    • iconOceanBase Loader and Dumper
    • iconOceanBase Deployer
    • iconKubernetes operator for OceanBase
    • iconOceanBase Diagnostic Tool
    • iconOceanBase Binlog Service
    • Connectors and Middleware
    • iconOceanBase Database Proxy
    • iconEmbedded SQL in C for OceanBase
    • iconOceanBase Call Interface
    • iconOceanBase Connector/C
    • iconOceanBase Connector/J
    • iconOceanBase Connector/ODBC
    • iconOceanBase Connector/NET
icon

OceanBase Migration Service

V4.2.13Community Edition

  • OMS Documentation
  • What's New
  • OMS Community Edition Introduction
    • What is OMS Community Edition?
    • Terms
    • OMS Community Edition HA
    • Architecture
      • Overview
      • Hierarchical functional system
      • Basic components
    • Limitations
  • Quick Start
    • Data migration process
    • Data synchronization process
  • Deploy OMS Community Edition
    • Deployment modes
    • System and network requirements
    • Memory and disk requirements
    • Prepare the environment
    • Deploy by using Docker
      • Single-node deployment
      • Single-region multi-node deployment
      • Multi-region multi-node deployment
      • Scale out
      • Check the deployment
      • Deploy a time-series database (Optional)
    • Deploy by using k8s
      • Single-node deployment
      • Single-region multi-node deployment
      • Multi-region multi-node deployment
      • Scale out
    • Integrate the OIDC protocol into OMS Community Edition to implement SSO
  • OMS Community Edition console
    • Log in to the console of OMS Community Edition
    • Overview
    • User center
      • Configure user information
      • Change your logon password
      • Log off
  • Data migration
    • Overview
    • Migrate data from a MySQL database to OceanBase Database Community Edition
    • Migrate data from HBase to OBKV
    • Migrate incremental data from OBKV to HBase
    • Migrate data from a Milvus database to OceanBase Database Community Edition
    • Migrate data from a Redis database to an OBKV-Redis database
    • Migrate data between tenants of OceanBase Database Community Edition
    • Migrate data in active-active disaster recovery scenarios
    • Migrate data from a TiDB database to OceanBase Database Community Edition
    • Migrate data from a PostgreSQL database to OceanBase Database Community Edition
    • Migrate data from Hive to OceanBase Database Community Edition
    • Migrate data from an ElasticSearch database to OceanBase Database Community Edition
    • Migrate data from OceanBase Database Community Edition to an ElasticSearch database
    • Migrate data from a MongoDB database to OceanBase Database Community Edition
    • Migrate data from a StarRocks database to OceanBase Database Community Edition
    • Migrate data from a Qdrant database to OceanBase Database Community Edition
    • Migrate data from a Doris database to OceanBase Database Community Edition
    • Migrate data from a ClickHouse database to OceanBase Database Community Edition
    • Manage data migration tasks
      • View details of a data migration task
      • Change the name of a data migration task
      • View and modify migration objects
      • Manage computing platforms
      • Use tags to manage data migration tasks
      • Perform batch operations on data migration tasks
      • Download and import settings of migration objects
      • Start and pause a data migration task
      • Release and delete a data migration task
    • Features
      • DML filtering
      • DDL synchronization
      • Configure matching rules for migration objects
      • Wildcard rules
      • Rename a database table
      • Use SQL conditions to filter data
      • Create and update a heartbeat table
      • Schema migration mechanisms
      • Schema migration operations
      • Set an incremental synchronization timestamp
      • Direct load
    • Supported DDL operations in incremental migration and limits
      • DDL synchronization from MySQL database to OceanBase Community Edition
        • Overview of DDL synchronization from a MySQL database to a MySQL-compatible tenant of OceanBase Database
        • CREATE TABLE
          • Create a table
          • Create a column
          • Create an index or a constraint
          • Create partitions
        • Data type conversion
        • ALTER TABLE
          • Modify a table
          • Operations on columns
          • Operations on constraints and indexes
          • Operations on partitions
        • TRUNCATE TABLE
        • RENAME TABLE
        • DROP TABLE
        • CREATE INDEX
        • DROP INDEX
        • DDL incompatibilities between MySQL database and OceanBase Community Edition
          • Overview
          • Incompatibilities of the CREATE TABLE statement
            • Incompatibilities of CREATE TABLE
            • Column types that are supported to create indexes or constraints
          • Incompatibilities of the ALTER TABLE statement
            • Incompatibilities of ALTER TABLE
            • Change the type of a constrained column
            • Change the type of an unconstrained column
            • Change the length of a constrained column
            • Change the length of an unconstrained column
            • Delete a constrained column
          • Incompatibilities of DROP INDEX operations
      • Supported DDL operations in incremental migration between MySQL-compatible tenants of OceanBase Database
      • Synchronize DDL operations from a PostgreSQL database to OceanBase Database
  • Data synchronization
    • Data synchronization overview
    • Create a task to synchronize data from OceanBase Database Community Edition to a Kafka instance
    • Create a task to synchronize data from OceanBase Database Community Edition to a RocketMQ instance
    • Manage data synchronization tasks
      • View details of a data synchronization task
      • Change the name of a data synchronization task
      • View and modify synchronization objects
      • Use tags to manage data synchronization tasks
      • Perform batch operations on data synchronization tasks
      • Download and import the settings of synchronization objects
      • Start and pause a data synchronization task
      • Release and delete a data synchronization task
    • Features
      • DML filtering
      • DDL synchronization
      • Configure matching rules for synchronization objects
      • Rename a topic
      • Use SQL conditions to filter data
      • Column filtering
      • Data format description
  • Create and manage data sources
    • Create data sources
      • Create an OceanBase-CE data source
      • Create a MySQL data source
      • Create a TiDB data source
      • Create a Kafka data source
      • Create a RocketMQ data source
      • Create a PostgreSQL data source
      • Create an HBase data source
      • Create a Qdrant data source
      • Create a Milvus data source
      • Create a Redis data source
      • Create a Hive data source
      • Create an ElasticSearch data source
      • Create a MongoDB data source
      • Create a StarRocks data source
      • Create a Doris data source
      • Create a ClickHouse data source
    • Manage data sources
      • View data source information
      • Copy a data source
      • Edit a data source
      • Delete a data source
      • Cache system views
    • Create a database user
    • User privileges
    • Enable binlogs for the MySQL database
  • OPS & Monitoring
    • O&M overview
    • Go to the overview page
    • Server
      • View server information
      • Update the quota
      • View server logs
      • Delete a server
    • Components
      • Store
        • Create a Store component
        • View details of a Store component
        • Update the configurations of a Store component
        • Start and pause a Store component
        • Delete a Store component
      • Incr-Sync
        • View details of an Incr-Sync component
        • Start and pause an Incr-Sync component
        • Migrate an Incr-Sync component
        • Update the configurations of an Incr-Sync component
        • Batch O&M
        • Delete an Incr-Sync component
      • Full-Import
        • View details of a Full-Import component
        • Pause a Full-Import component
        • Rerun and resume a Full-Import component
        • Update the configurations of a Full-Import component
        • Delete a Full-Import component
      • Full-Verification
        • View details of a Full-Verification component
        • Pause a Full-Verification component
        • Rerun and resume a Full-Verification component
        • Update the configurations of a Full-Verification component
        • Delete a Full-Verification component
      • Component parameters
        • Coordinator
        • Condition
        • Source Plugin
          • Overview
          • StoreSource
          • DataFlowSource
          • LogProxySource
          • KafkaSource (TiDB)
          • HBaseSource
          • HiveSource
          • ElasticSearchSource
          • MongoDBSource
        • Sink Plugin
          • Overview
          • JDBC-Sink
          • KafkaSink
          • DatahubSink
          • RocketMQSink
          • HBaseSink
          • HiveSink
        • Store parameters
          • Parameters of a MySQL store
          • Parameters of an OceanBase store
          • ElasticSearch Store
          • MongoDB Store
        • Parameters of the CM component
        • Parameters of the Supervisor component
        • Parameters of the Full-Verification component
    • O&M Task
      • View O&M tasks
      • Skip a task or subtask
      • Retry a task or subtask
  • System management
    • Permission Management
      • Overview
      • Manage users
      • Manage departments
    • Alert center
      • View task alerts
      • View system alerts
      • Manage alert settings
    • Associate with OCP clusters
    • System parameters
      • Modify system parameters
      • Modify HA configurations
    • SSO management
      • Overview
      • Create an SSO integration
      • Enable or disable an SSO integration
      • Edit an SSO integration
      • Delete an SSO integration
  • OMS Community Edition O&M
    • Manage OMS services
    • OMS logs
    • Component O&M
      • O&M operations for the Supervisor component
      • CLI-based O&M for the Connector component
      • O&M operations for the Store component
    • Component tuning
      • Full/Incremental data migration performance optimization
    • Set throttling
  • Reference Guide
    • API Reference
      • Overview
      • CreateProject
      • StartProject
      • StopProject
      • ResumeProject
      • ReleaseProject
      • DeleteProject
      • ListProjects
      • DescribeProject
      • DescribeProjectSteps
      • DescribeProjectStepMetric
      • DescribeProjectProgress
      • DescribeProjectComponents
      • ListProjectFullVerifyResult
      • StartProjectsByLabel
      • StopProjectsByLabel
      • CreateMysqlDataSource
      • CreateMySQLMasterSlaveDataSource
      • CreateOceanBaseDataSource
      • CreateKafkaDataSource
      • ListDataSource
      • DeleteDataSource
      • CreateLabel
      • ListAllLabels
      • ListFullVerifyInconsistenciesResult
      • ListFullVerifyCorrectionsResult
      • UpdateStore
      • UpdateFullImport
      • UpdateIncrSync
      • UpdateFullVerification
      • UploadFile
      • SubmitPreCheck
      • GetPreCheckResult
      • RetryPreCheck
    • OMS error codes
    • Alert Reference
      • oms_host_down
      • oms_host_down_migrate_resource
      • oms_host_threshold
      • oms_migration_failed
      • oms_migration_delay
      • oms_sync_failed
      • oms_sync_status_inconsistent
      • oms_sync_delay
    • Telemetry parameters
    • Create a trigger
  • Upgrade Guide
    • Overview
    • Single-node upgrade
    • Multi-node upgrade
    • Hot upgrade of OMS Community Edition
    • Upgrade the CDC library
    • FAQ
  • FAQ
    • General O&M
      • How do I modify the resource quotas of an OMS container?
      • Clear files in the Store component
      • How do I troubleshoot the OMS server down issue?
      • Deploy InfluxDB for OMS
      • Increase the disk space of the OMS host
    • Task diagnostics
      • What do I do when a store does not have data of the timestamp requested by the downstream?
      • What do I do when OceanBase Store failed to access an OceanBase cluster through RPC?
    • OPS & monitoring
      • What are the alert rules?
    • Data synchronization
      • FAQ about synchronization to a message queue
        • What are the strategies for ensuring the message order in incremental data synchronization to Kafka
      • Performance troubleshooting and tuning for data synchronization from OceanBase Community Edition to Kafka
    • Data migration
      • Full migration
        • How do I query the ID of a checker?
        • How do I query log files of the Checker component of OMS?
        • How do I query the verification result files of the Checker component of OMS?
        • Garbled characters in the Latin1 character set
        • What do I do if the target table does not exist?
        • What can I do when the full migration failed due to LOB fields?
        • What do I do if garbled characters cannot be written into OceanBase Database V3.1.2?
      • Incremental synchronization
        • How do I skip DDL statements?
        • How do I update allowlists and blocklists?
        • What are the application scope and limits of ETL?
    • Logon and password
      • What do I do if my logon password is locked?
    • Installation and deployment
      • How do I upgrade Store?
      • What do I do when the "Failed to fetch" error is reported?
      • Change port numbers for components
      • Switching between the primary and standby OMS MetaDBs

Download PDF

OMS Documentation What's New What is OMS Community Edition? Terms OMS Community Edition HA Overview Hierarchical functional system Basic components Limitations Data migration process Data synchronization process Deployment modes System and network requirements Memory and disk requirements Prepare the environment Single-node deployment Single-region multi-node deployment Multi-region multi-node deployment Scale out Check the deployment Deploy a time-series database (Optional) Single-node deployment Single-region multi-node deployment Multi-region multi-node deployment Scale out Integrate the OIDC protocol into OMS Community Edition to implement SSO Log in to the console of OMS Community Edition Overview Configure user information Change your logon password Log off Overview Migrate data from a MySQL database to OceanBase Database Community Edition Migrate data from HBase to OBKV Migrate incremental data from OBKV to HBase Migrate data from a Milvus database to OceanBase Database Community Edition Migrate data from a Redis database to an OBKV-Redis database Migrate data between tenants of OceanBase Database Community Edition Migrate data in active-active disaster recovery scenarios Migrate data from a TiDB database to OceanBase Database Community Edition Migrate data from a PostgreSQL database to OceanBase Database Community Edition Migrate data from Hive to OceanBase Database Community Edition Migrate data from an ElasticSearch database to OceanBase Database Community Edition Migrate data from OceanBase Database Community Edition to an ElasticSearch database Migrate data from a MongoDB database to OceanBase Database Community Edition Migrate data from a StarRocks database to OceanBase Database Community Edition Migrate data from a Qdrant database to OceanBase Database Community Edition Migrate data from a Doris database to OceanBase Database Community Edition Migrate data from a ClickHouse database to OceanBase Database Community Edition View details of a data migration task Change the name of a data migration task View and modify migration objects Manage computing platforms Use tags to manage data migration tasks Perform batch operations on data migration tasks Download and import settings of migration objects Start and pause a data migration task Release and delete a data migration task DML filtering DDL synchronization Configure matching rules for migration objects Wildcard rules Rename a database table Use SQL conditions to filter data Create and update a heartbeat table Schema migration mechanisms Schema migration operations Set an incremental synchronization timestamp Direct load Supported DDL operations in incremental migration between MySQL-compatible tenants of OceanBase Database Synchronize DDL operations from a PostgreSQL database to OceanBase Database Data synchronization overview Create a task to synchronize data from OceanBase Database Community Edition to a Kafka instance Create a task to synchronize data from OceanBase Database Community Edition to a RocketMQ instance View details of a data synchronization task Change the name of a data synchronization task View and modify synchronization objects Use tags to manage data synchronization tasks Perform batch operations on data synchronization tasks Download and import the settings of synchronization objects Start and pause a data synchronization task Release and delete a data synchronization task DML filtering DDL synchronization Configure matching rules for synchronization objects Rename a topic Use SQL conditions to filter data Column filtering Data format description Create an OceanBase-CE data source Create a MySQL data source Create a TiDB data source Create a Kafka data source Create a RocketMQ data source Create a PostgreSQL data source Create an HBase data source Create a Qdrant data source Create a Milvus data source Create a Redis data source Create a Hive data source
OceanBase logo

The Unified Distributed Database for the AI Era.

Follow Us
Products
OceanBase CloudOceanBase EnterpriseOceanBase Community EditionOceanBase seekdb
Resources
DocsBlogLive DemosTraining & Certification
Company
About OceanBaseTrust CenterLegalPartnerContact Us
Follow Us

© OceanBase 2026. All rights reserved

Cloud Service AgreementPrivacy PolicySecurity
Contact Us
Document Feedback
  1. Documentation Center
  2. OceanBase Migration Service
  3. V4.2.13
iconOceanBase Migration Service
V 4.2.13Community Edition
Enterprise Edition
  • V 4.3.2
  • V 4.3.1
  • V 4.3.0
  • V 4.2.5
  • V 4.2.4
  • V 4.2.3
  • V 4.0.2
  • V 3.4.0
Community Edition
  • V 4.2.13
  • V 4.2.12
  • V 4.2.11
  • V 4.2.10
  • V 4.2.9
  • V 4.2.8
  • V 4.2.7
  • V 4.2.6
  • V 4.2.5
  • V 4.2.4
  • V 4.2.3
  • V 4.2.1
  • V 4.2.0
  • V 4.0.0
  • V 3.3.1

Overview

Last Updated:2026-04-16 07:09:24  Updated
share
What is on this page
Background information
Principles
OAuth 2.0
OIDC
Login scenarios
View the SSO list

folded

share

You can log in to the homepage of OceanBase Migration Service (OMS) Community Edition by using an external account service of the OAuth 2.0 or OpenID Connect (OIDC) type.

Background information

Single sign-on (SSO) is an authentication method that allows you to securely authenticate to OMS Community Edition. OMS Community Edition supports SSO integration with OAuth 2.0 and OIDC.

  • OAuth (Open Authorization) is an open standard for authorization. It allows you to authorize a third-party application to access protected information stored on a resource server without providing your username and password to the third-party application. This decouples authentication from authorization. OAuth is an international standard that is widely adopted and continuously used. OAuth 2.0 is an updated version of OAuth that is more secure and easier to implement, but it is not compatible with OAuth 1.0. OAuth defines a secure, open, and simple standard for authorizing user resources. Third-party applications can obtain user authorization information without needing the user's account and password.

    • OAuth 2.0 is a delegated authorization framework for REST/APIs.

    • OAuth 2.0 is a token-based authorization method. It allows an application to obtain limited access to user data without exposing the user's password.

    • OAuth 2.0 decouples authentication from authorization.

  • OIDC (OpenID Connect) is a secure authentication mechanism. A third-party application connects to an identity provider to obtain user information and returns this information reliably to the third-party application. OIDC extends the OAuth 2.0 protocol by adding an ID Token field that provides basic user information. ID Tokens are encapsulated in JSON Web Token (JWT) format, providing self-containment and tamper-proofing, making them safe to pass to third-party applications and easy to verify.

Principles

OAuth 2.0

OMS Community Edition is compatible with standard OAuth 2.0 authentication centers and currently only supports the authorization code (authorization-code) mode. In this mode, an application uses an authorization code to request an access token or refresh token from the authorization server.

1

The authorization process involves the following steps:

  1. The user logs in to the application system and requests a redirect to the authentication server, which returns a 302 response to the login authentication page.

  2. The user enters their authentication information. The authentication server verifies the information and returns a code to the application system.

  3. The application system uses the code to request an access token from the authentication server. The authentication server verifies the client ID and code and sends an access token to the application system.

  4. The application system uses the access token to query the user's login information. The authentication server returns the user's information, such as the username.

  5. The application system verifies the username and creates a session, then redirects to the redirect_uri.

Step Parameter Description
Step 1 Authorization Request
  • response_type: Required. The value is fixed to code.
  • client_id: Required. The ID of the third-party application.
  • state: Recommended. A string provided by the client, which is returned to the client unchanged by the server.
  • redirect_uri: Required. The redirect URL after authorization is successful.

    Note

    The URL to which the authorization server redirects to OMS Community Edition. If the SSO has a callback allowlist, it needs to be added to the allowlist.

  • scope: Optional. Specifies the authorization scope.
Step 2 Verify the parameters passed in Step 1. Display the login page to allow the user to authenticate. The user authorizes the client to access the resources.
Step 3 Authorization Response
Redirect to the redirect_uri specified in Step 1 and return the following parameters:
  • code: The authorization code.
  • state: The state parameter provided by the client in Step 1, returned unchanged.
Step 4 Access Token Request
  • grant_type: Required. The value is fixed to authorization_code.
  • code: Required. The code returned in the Authorization Response.
  • redirect_uri: Required. Must be the same as the redirect_uri provided in the Authorization Request.
  • client_id: Required. Must be the same as the client_id provided in the Authorization Request.
Step 5 Access Token Response
  • access_token: The access token.
  • refresh_token: Optional. The refresh token.
  • expires_in: The expiration time.

OIDC

1

  1. The client sends an authentication request to the authentication service.

  2. The user authorizes the client on the authentication page.

  3. The authentication service verifies the authentication request and returns a code to the client.

  4. The client requests the callback interface from the business service, including the code.

  5. The business service requests the authentication service to issue a token, including the code, client ID, and client secret.

  6. The authentication service verifies the request and returns an ID token.

  7. The authentication is successful, and the business service returns the ID token to the client.

  8. The client requests the business service, including the ID token.

  9. The business service verifies the ID token and returns the business response.

Login scenarios

  • When SSO mode and local login mode are enabled, users can log in using their local account credentials or third-party account credentials.

  • When SSO mode is enabled and local login mode is not, users can directly log in to OMS Community Edition using third-party account credentials. During the first login, they are redirected to the third-party authorization login page. After authorization, subsequent logins are direct.

  • When SSO mode is not enabled, only local account credentials can be used for login.

View the SSO list

If you are logged in to OMS Community Edition as an ADMIN or ADMIN_VIEWER role, you can view the details of SSO integrations on the SSO Management page. This includes the configuration name, type, creator, creation time, last modified time, and whether local login mode is enabled. You can also perform common O&M operations. For more information, see Create an SSO integration, Enable or disable an SSO integration, Edit an SSO integration, and Delete an SSO integration.

Previous topic

Modify HA configurations
Last

Next topic

Create an SSO integration
Next
What is on this page
Background information
Principles
OAuth 2.0
OIDC
Login scenarios
View the SSO list