Configure OpenID Connect SSO
Set up single sign-on with an OpenID Connect provider in the Console. For other providers shown in the Console, contact TaruviBase support.
- In the target site, open Authentication → SSO Providers, then choose OpenID Connect.
- Enter Provider ID, Server URL (Discovery Endpoint), Display Name, Client ID, and Client Secret. Add optional Icon and leave Auto-redirect off until testing succeeds.
- Create or edit the provider, then complete a non-production sign-in before enabling Auto-redirect.
- The secret is write-only and masked after create/save. Rotate it by entering the verified replacement secret, saving, and repeating the non-production test.
If discovery or client validation fails, correct the displayed field, save, and repeat the non-production sign-in before enabling Auto-redirect.
Delete an OIDC provider
Confirm deletion
- Affected resource and cascade: SSO providers are shared across sites, so check every site whose sign-in uses this provider.
- Reversibility: Treat deletion as irreversible; the masked Client Secret cannot be recovered from the record.
- Authorization: Confirm you are allowed to change this shared provider.
- Backup or export: Note the provider's settings. The Client Secret can't be read back, so keep it in your secret manager.
- Confirmation: Confirm the exact Provider ID and the affected sites.
- Success response and postcondition: Confirm the Console no longer lists the provider and that hosted sign-in no longer redirects to it.
- Recovery: Recreate the provider in the Console with the saved settings and secret.
Cannot Delete Provider is shown while connected users exist. Move those users to another sign-in method first; to unlink users from a provider, contact TaruviBase support. Delete the OpenID Connect provider only after that condition and the warning controls are met.
For unresolved provider failures, see troubleshooting.