SSO is available on the Enterprise plan or through an explicit feature override. Only the team Owner can manage it.
Prepare the identity provider
Create a web OIDC application with the callback displayed on the Qwairy SSO page. The default callback path is:Create the connection
- Enter a provider display name.
- Enter the issuer URL, Client ID, and Client Secret.
- Choose the default role for just-in-time provisioning.
- Save the connection.
- Use Test OIDC Connection to check discovery and signing-key access.
Verify a domain
Add the organization’s email domain, then publish the TXT record shown by the interface. Select Verify after DNS can resolve the record. Each domain can belong to one SSO connection. Removing the last verified domain disables SSO and enforcement for that connection.Enable and enforce
You need at least one verified domain before enabling SSO. Matching users can then authenticate through the configured provider and be provisioned with the default role. Enforce SSO requires SSO to be enabled. Test sign-in with the intended domain before enforcement. Users whose matching identity cannot authenticate may otherwise lose access.Troubleshooting
- Discovery failed: check the issuer root URL and network access to its discovery document and JWKS.
- Redirect mismatch: copy the exact origin and
/api/auth/sso/callbackpath shown in Qwairy. - Domain not verified: confirm the TXT host and value in public DNS.
- User not provisioned: confirm a verified email claim, matching domain, and default role.

