Skip to main content
SSO is available on the Enterprise plan or through an explicit feature override. Only the team Owner can manage it.
Open Team Management > SSO to configure an OpenID Connect provider using the Authorization Code flow with PKCE.

Prepare the identity provider

Create a web OIDC application with the callback displayed on the Qwairy SSO page. The default callback path is:
The origin must match the domain used for sign-in. A white-label custom domain therefore requires its own callback origin. Collect the issuer URL, Client ID, and Client Secret. The issuer should support OIDC discovery and JWKS retrieval.

Create the connection

  1. Enter a provider display name.
  2. Enter the issuer URL, Client ID, and Client Secret.
  3. Choose the default role for just-in-time provisioning.
  4. Save the connection.
  5. Use Test OIDC Connection to check discovery and signing-key access.
The available default roles are Member and Viewer. A newly provisioned Viewer still needs brand access before viewing a workspace.

Verify a domain

Add the organization’s email domain, then publish the TXT record shown by the interface. Select Verify after DNS can resolve the record. Each domain can belong to one SSO connection. Removing the last verified domain disables SSO and enforcement for that connection.

Enable and enforce

You need at least one verified domain before enabling SSO. Matching users can then authenticate through the configured provider and be provisioned with the default role. Enforce SSO requires SSO to be enabled. Test sign-in with the intended domain before enforcement. Users whose matching identity cannot authenticate may otherwise lose access.

Troubleshooting

  • Discovery failed: check the issuer root URL and network access to its discovery document and JWKS.
  • Redirect mismatch: copy the exact origin and /api/auth/sso/callback path shown in Qwairy.
  • Domain not verified: confirm the TXT host and value in public DNS.
  • User not provisioned: confirm a verified email claim, matching domain, and default role.
Deleting the SSO connection also removes its associated domain records from Qwairy. Coordinate the change before deletion.