Sign-in options
A local deployment can begin in single-operator mode without an SSO plugin. Organizations can add a supported sign-in provider through the plugin system when they are ready to control access for multiple operators.
- Keep at least one tested owner recovery path before enforcing SSO.
- For a manual-provisioning provider, create approved users before they attempt to sign in.
- Verify logout, disabled-user, and expired-session behavior before rollout.
Provider setup
- Create the application in the identity provider.
- Set the exact callback URL shown by OpenNeko.
- Store the client secret through the supported secret field.
- Test with a non-owner account.
- Enable enforcement only after the recovery path is confirmed.
Sign-in is not a connected account
SSO proves who the operator is. A connected account grants that person access to another service such as Slack or a commerce platform. Configure and revoke those grants separately.