Sign-in and single sign-on
How people sign in depends on where Noset runs.
People sign in only through your company’s identity provider (OIDC). You set it up in the setup wizard and change it under Settings › Sign-in: the issuer, the client id and secret, and the scopes. Register the Callback URL the page shows as a redirect URI at your identity provider.
A change takes effect only after a test sign-in works; if it fails, nothing changes.
People type their email address.
- If their domain is verified by an organization that connected its identity provider, they sign in there.
- Everyone else gets a one-time sign-in link by email. It works once, for 15 minutes.
An organization’s admins can connect their own identity provider under Settings › Sign-in.
Single sign-on in Noset Cloud
Section titled “Single sign-on in Noset Cloud”-
Connect your identity provider. Under Single sign-on, enter the issuer, client id and secret, and register the callback URL at your provider. Your test sign-in must vouch for your own address.
-
Verify your domains. Under Verified domains, add a domain. Add the TXT record the page shows at your DNS provider: name
_noset.<domain>, valuenoset-verify=…. Then verify. DNS can take a while; try again if the record is not visible yet. A domain belongs to one organization at most. -
Require single sign-on (optional). Available once single sign-on is saved and tested and one domain is verified. People of your verified domains then sign in only through your provider.
While single sign-on is required:
- Guests from other domains keep signing in with email links.
- Admins can still open the organization with an email link, as a break-glass way in. Each use is recorded in the audit log.
- Turning the requirement off waits for a second admin when there is one. See Admin changes.
Your identity provider only vouches for addresses of the domains you verified; a sign-in with any other address is refused.