Single sign-on
Owners of an Enterprise organization can connect it to their identity provider under Settings → Single sign-on. People at your verified domains then sign in through the provider, join the organization the first time they do, and get the role their groups map to.
Updawg speaks OpenID Connect, which Okta, Microsoft Entra ID and Google Workspace all support. SAML is not supported yet.
1. Verify your domain
Section titled “1. Verify your domain”Add the domain your people’s addresses are at (for example example.com).
Updawg shows a TXT record to publish:
| Name | Value |
|---|---|
_updawg.example.com |
updawg-verification=… |
Publish it with your DNS provider and press Verify. DNS changes can take a few minutes to be seen.
Only addresses at a verified domain can sign in through your provider — however the provider is configured, it can only vouch for your own domains. A domain can be verified by one Updawg organization at a time.
2. Register Updawg with your provider
Section titled “2. Register Updawg with your provider”Create a web application (OpenID Connect, authorization code flow) and set its sign-in redirect URI to the one shown in Settings:
https://api.updawg.net/v1/auth/sso/callback| Provider | Issuer |
|---|---|
| Okta | https://<your-org>.okta.com |
| Microsoft Entra ID | https://login.microsoftonline.com/<tenant-id>/v2.0 |
| Google Workspace | https://accounts.google.com |
Copy the client ID and client secret into Settings. The secret is stored encrypted and never shown again; leave the field empty when saving later changes to keep it. Updawg reads the issuer’s discovery document when you save, so a mistyped issuer is caught there.
3. Roles from groups
Section titled “3. Roles from groups”Map group names to admin, operator or viewer. A person gets the highest role any of their groups maps to, updated each time they sign in. Choose what happens to somebody no mapping matches: refused, or a default role.
- Okta: add a groups claim to the ID token (Sign On → OpenID Connect ID Token → Groups claim).
- Entra ID: add the groups claim (Token configuration). Entra sends group object IDs, so map those IDs.
- Google Workspace sends no groups: use a default role.
Owners are never made or changed by a sign-in. Ownership is given by a person in Updawg, so a mistake in a mapping cannot demote the people who would fix it.
4. Enable, then require
Section titled “4. Enable, then require”Enabled lets people at your verified domains sign in through the provider. The sign-in page notices their address and offers it.
Required closes every other way in for those addresses — emailed links, GitHub and the sign-up form — so access follows your identity provider alone. The organization’s owners are exempt, so an outage at the provider is not a lock-out. Require it only after somebody has signed in successfully.
Removing the connection leaves everybody a member; they sign in with an emailed link from then on.