01
1. Collect IdP metadata
- For SAML, collect the entity ID, SSO URL, and X.509 certificate from the identity provider.
- For OIDC, collect the issuer URL, client ID, and client secret. Keep the original secret in your organization's approved secret store.
- If you set an enforced email domain, record the intended policy. Enforcement depends on the login flow, which is not active yet.
02
2. Save and verify
- Open /settings/sso, choose the protocol, enter the fields, and save. Compare the displayed certificate fingerprint with the value supplied by the identity administrator.
- Today this feature stores metadata only. Users cannot sign in through SAML or OIDC until the separate login flow is implemented.
- Use Remove to delete the stored configuration. Do not communicate the tenant as SSO-enabled while only metadata is present.