Skip to content

Single sign-on

Owners of an Enterprise organization can connect it to their identity provider under Settings → Single sign-on. People at your verified domains then sign in through the provider, join the organization the first time they do, and get the role their groups map to.

Updawg speaks OpenID Connect, which Okta, Microsoft Entra ID and Google Workspace all support. SAML is not supported yet.

Add the domain your people’s addresses are at (for example example.com). Updawg shows a TXT record to publish:

Name Value
_updawg.example.com updawg-verification=…

Publish it with your DNS provider and press Verify. DNS changes can take a few minutes to be seen.

Only addresses at a verified domain can sign in through your provider — however the provider is configured, it can only vouch for your own domains. A domain can be verified by one Updawg organization at a time.

Create a web application (OpenID Connect, authorization code flow) and set its sign-in redirect URI to the one shown in Settings:

https://api.updawg.net/v1/auth/sso/callback
Provider Issuer
Okta https://<your-org>.okta.com
Microsoft Entra ID https://login.microsoftonline.com/<tenant-id>/v2.0
Google Workspace https://accounts.google.com

Copy the client ID and client secret into Settings. The secret is stored encrypted and never shown again; leave the field empty when saving later changes to keep it. Updawg reads the issuer’s discovery document when you save, so a mistyped issuer is caught there.

Map group names to admin, operator or viewer. A person gets the highest role any of their groups maps to, updated each time they sign in. Choose what happens to somebody no mapping matches: refused, or a default role.

  • Okta: add a groups claim to the ID token (Sign On → OpenID Connect ID Token → Groups claim).
  • Entra ID: add the groups claim (Token configuration). Entra sends group object IDs, so map those IDs.
  • Google Workspace sends no groups: use a default role.

Owners are never made or changed by a sign-in. Ownership is given by a person in Updawg, so a mistake in a mapping cannot demote the people who would fix it.

Enabled lets people at your verified domains sign in through the provider. The sign-in page notices their address and offers it.

Required closes every other way in for those addresses — emailed links, GitHub and the sign-up form — so access follows your identity provider alone. The organization’s owners are exempt, so an outage at the provider is not a lock-out. Require it only after somebody has signed in successfully.

Removing the connection leaves everybody a member; they sign in with an emailed link from then on.