Skip to main content

Configure OpenID Connect SSO

Set up single sign-on with an OpenID Connect provider in the Console. For other providers shown in the Console, contact TaruviBase support.

  1. In the target site, open Authentication → SSO Providers, then choose OpenID Connect.
  2. Enter Provider ID, Server URL (Discovery Endpoint), Display Name, Client ID, and Client Secret. Add optional Icon and leave Auto-redirect off until testing succeeds.
  3. Create or edit the provider, then complete a non-production sign-in before enabling Auto-redirect.
  4. The secret is write-only and masked after create/save. Rotate it by entering the verified replacement secret, saving, and repeating the non-production test.

If discovery or client validation fails, correct the displayed field, save, and repeat the non-production sign-in before enabling Auto-redirect.

Delete an OIDC provider​

Confirm deletion
  • Affected resource and cascade: SSO providers are shared across sites, so check every site whose sign-in uses this provider.
  • Reversibility: Treat deletion as irreversible; the masked Client Secret cannot be recovered from the record.
  • Authorization: Confirm you are allowed to change this shared provider.
  • Backup or export: Note the provider's settings. The Client Secret can't be read back, so keep it in your secret manager.
  • Confirmation: Confirm the exact Provider ID and the affected sites.
  • Success response and postcondition: Confirm the Console no longer lists the provider and that hosted sign-in no longer redirects to it.
  • Recovery: Recreate the provider in the Console with the saved settings and secret.

Cannot Delete Provider is shown while connected users exist. Move those users to another sign-in method first; to unlink users from a provider, contact TaruviBase support. Delete the OpenID Connect provider only after that condition and the warning controls are met.

For unresolved provider failures, see troubleshooting.