Restrict project login to specific identity provider categories defined in Reunite. This configuration determines which IdPs are available for logging in to a project. Configuring SSO by itself does not require users to log in to access a project. To require login to a project, rbac or requiresLogin must also be configured.
| Option | Type | Description |
|---|---|---|
sso | [string] | List of identity provider categories from Reunite. Possible values: To target a specific identity provider by its unique ID, use Default value: |
The recommended way to configure sso is within the access object:
access:
sso:
- GUEST
- REDOCLY
The following example disables SSO using the access object:
access:
sso: []
You might apply this configuration to a project that also has rbac configured. In that case, pages assigned to the authenticated default team are not accessible to anyone. Otherwise, if you do not have rbac configured, or you have all pages assigned to the anonymous default team, all pages are accessible.
Root-level sso configuration displays warnings when the access object is present. Migrate to the access object format.
sso:
- GUEST
- REDOCLY
- Access configuration - Group authentication and access settings together using the
accessobject - RBAC configuration - Complete options for configuring role-based access control for granular project permissions and user management
- RequiresLogin configuration - Require login for all users to your project without implementing complex role-based access control
- Configure Google Workspace as a SAML SSO - Integrate Google Workspace SAML 2 SSO with Reunite for enterprise authentication workflows
- Single sign-on and login - Understand different identity provider categories in Reunite and how they apply to project authentication
- Add identity providers - Follow steps to add identity providers in Reunite for centralized authentication management
- Configure project SSO - Enable multiple identity provider categories to give users flexible authentication options for your projects