DocumentationSSO and sign-in
Docs/Secure and govern

SSO and sign-in

Choose how operators authenticate and keep identity control with the deployment owner.

Sign-in options

A local deployment can begin in single-operator mode without an SSO plugin. Organizations can add a supported sign-in provider through the plugin system when they are ready to control access for multiple operators.

  • Keep at least one tested owner recovery path before enforcing SSO.
  • For a manual-provisioning provider, create approved users before they attempt to sign in.
  • Verify logout, disabled-user, and expired-session behavior before rollout.

Provider setup

  1. Create the application in the identity provider.
  2. Set the exact callback URL shown by OpenNeko.
  3. Store the client secret through the supported secret field.
  4. Test with a non-owner account.
  5. Enable enforcement only after the recovery path is confirmed.

Sign-in is not a connected account

SSO proves who the operator is. A connected account grants that person access to another service such as Slack or a commerce platform. Configure and revoke those grants separately.