Skip to content

Manage Providers

This page covers the day-to-day management of sign-in providers in the Providers tab: testing, editing, enabling, disabling, and deleting them. You can search providers by name and sort them by name or created date.

Permissions

Only users with the Admin role can manage sign-in providers. See the Permissions page for details.

Test a Provider

The Test button at the bottom of the provider form runs connection diagnostics for OIDC and SAML providers, against the values currently in the form (or the saved configuration when nothing was changed).

test-provider-results

The Test Results panel opens with a summary line ("All checks passed", "N of M checks failed", or "N of M checks need review") and a scope line telling you what was tested: "Reflects the configuration currently in this form." or "Reflects the saved configuration." Each check shows a Passed, Failed, Warning, or Skipped badge; expand a check to read the details.

Which checks run depends on the provider type. An OIDC provider is tested for its Discovery URL, Authorization Endpoint, Token Endpoint, UserInfo Endpoint, JWKS URI, Issuer, Redirect URI, Client Credentials, Groups Claim, Scopes, Claim Mapping, Email Claim, and Login Flow. A SAML provider is tested for its IdP Metadata URL, X.509 Certificate, SP Metadata, SSO URL, Attribute Mapping, Groups Claim, and Login Flow.

Two OIDC checks deserve a closer look:

  • JWKS URI fails when no JWKS URI is configured, when the document is unreachable, or when it contains no keys. It passes with "JWKS is reachable and publishes N signing key(s)".
  • Issuer compares the configured Issuer against the discovery document character for character, so even a trailing slash difference fails it, and the failure message warns that every ID token would be rejected at sign-in. Without a discovery URL the check passes with a note that the value could not be cross-checked, and when the discovery document is unreachable it comes back as a Warning instead.

Tip

Test a provider before enabling it, and again after any change to its endpoints or certificates. Diagnostics do not apply to the Email & Password provider, which has no external connection to test.

Edit a Provider

Step 1: Click the vertical ellipsis next to the provider you want to edit.

step-1-click-ellipsis

Step 2: A menu appears with the available actions. Click Edit .

step-2-click-edit

Step 3: Update the fields as needed. Secrets (client secret, certificate) are never displayed; enter a new value only to replace the stored one.

step-3-edit-modal

Step 4: Click the Save button.

step-4-click-save

Step 5: A success message appears.

step-5-success

Some changes sign users out

Saving a security-sensitive change (credentials, certificates, or a more restrictive domain or group policy) ends every active session issued by the provider, including your own if you signed in with it. The form warns you first, lists the changes that caused it, and asks you to confirm with Save and Sign Everyone Out.

Changes that affect sign-in are verified before saving

On any enabled OIDC or SAML provider, a change that affects sign-in is saved only after the connection diagnostics pass, and the same applies when you enable a provider. That covers the endpoints and metadata, certificates and client credentials, scopes, the claim or attribute mapping, and the groups claim. Checks that come back as warnings do not stand in the way; a check that fails does, and the form names the failing checks so you can correct the values and try again. Saving a provider that stays disabled is never gated, which is what lets you correct a configuration while its identity provider is unreachable.

Independently of the diagnostics, the form refuses to save an OIDC provider that is missing a required connection or endpoint value, the JWKS URI and the Issuer among them. The error message names the fields that are missing.

Enable or Disable a Provider

Each provider row has an Enabled / Disabled control:

  • Enable makes the provider available on the sign-in page.
  • Disable immediately ends every active session issued by the provider. Sign in through a different provider before disabling it.

Step 1: Click Enabled on the provider's row.

enable-provider

Step 2: A success message appears.

enable-success

Step 1: Click Disabled on the provider's row.

disable-provider

Step 2: A confirmation dialog explains that every active session issued by the provider ends. Click Disable and Sign Everyone Out to proceed.

disable-confirmation

Step 3: A success message appears.

disable-success

Note

The last enabled customer sign-in provider cannot be disabled, and you cannot disable the provider your current session signed in with. This keeps you from locking everyone (or yourself) out.

Delete a Provider

Step 1: Click the vertical ellipsis next to the provider you want to delete.

step-1-delete-ellipsis

Step 2: A menu appears with the available actions. Click Delete .

step-2-click-delete

Step 3: A confirmation modal appears showing the provider's name and type. Deleting a provider removes all of its configuration and cannot be undone.

step-3-delete-modal

Step 4: Click the Delete button to confirm. A success message appears and the provider leaves the list.

step-4-delete-success

Note

A provider with users still associated to it cannot be deleted. Disable it instead. The last enabled customer sign-in provider cannot be deleted either. Deletion is permanent, so prefer disabling when you may need the configuration again.