Team
SSO
Let your team sign in with your OpenID Connect identity provider.
Connect your identity provider
Each team can have one OIDC connection. Team admins set it up in Settings → SSO:
- Register an application with your identity provider, using the Callback URL shown on the page (
<dashboard origin>/api/auth/oauth2/callback/<team ID>). - Enter the Issuer URL, Client ID and Client secret, and click Save connection.
- Click Test connection and complete a sign-in with an identity that has a verified email address. When it succeeds, the page shows Connection test passed.
- Turn on Enable SSO. From then on, members must use the identity provider to work in this team.
The provider must support the iss parameter in authorization responses. The client secret is encrypted and never shown again.
How members sign in
- An existing member links SSO while signed in to their Opensend account, with Continue with SSO under Authentication on their profile. Later SSO sign-ins use that link.
- New people still need an invitation. The identity provider cannot take over an existing account just by asserting its email, and email domains never grant membership.
- Enforcement applies to the team, not the account: signing in with a password still reaches account settings and other teams.
Change or recover the connection
Saving new provider settings turns enforcement off until another successful test, and every member must link again.
If a broken provider locks the team out, an operator with the deployment admin key can turn enforcement off from the app checkout:
bash
pnpm backend run sso:recover '{"organizationId":"YOUR_TEAM_ID"}'This also clears the connection test. It does not reveal the client secret or grant membership. See recovering an account.