Set up single sign-on and automatic user provisioning
A task guide: the pages to use, in order.
Steps
- Copy the redirect URI. Identity provider tab
- Create an OIDC web app at your provider. Authorization code with PKCE; scopes openid, email, profile
- Enter issuer, client ID, domains and secret. Save secret, then Save settings
- Click Test discovery. It should read your signing keys
- Switch single sign-on on and test it yourself. Use a private browser window
- Create a SCIM token. SCIM provisioning tab; copy it once
- Check new accounts arrive. Deactivated users show as Locked
- Turn on Require single sign-on. Password sign-in is refused for your domains