Skip to content

Sign-In Providers Introduction

  • Managed deployment
  • Self-hosted

Sign-In Providers let administrators configure how users sign in to Qualytics directly from the platform, without deployment-level setup. From Settings > Access, you can set up and manage multiple sign-in providers (OIDC and SAML identity providers, plus email and password sign-in), invite new users, review requests to link a new sign-in identity to an existing account, and audit sign-in activity.

The sign-in page shows one button for each enabled identity provider, so users pick how they authenticate. When email and password sign-in is enabled, the page shows the credentials form instead of a button for it.

Providers tab on the Access settings page

Permissions

Only users with the Admin role see the Providers, Link approvals, Invitations, and Log tabs on the Access settings page. See the Permissions page for details.

Getting started

A new deployment offers one-time initial administrator enrollment. Once signed in, configure and test your providers here. Enabling a provider makes it available on the sign-in page, so keep a working Admin sign-in while making changes. See Managed Deployment SSO Setup or Self-Hosted Authentication Setup.


Deep Dive

Understand the provider types, the sign-in experience, identity linking, access restrictions, and sessions.

  • How It Works


    Provider types, the sign-in experience, provisioning, identity linking, access restrictions, sessions, and the audit trail.

    How It Works

  • Permissions


    Roles required to manage providers, approvals, invitations, and the sign-in log.

    Permissions


How-tos

Set up and operate your sign-in providers.

  • Add an OIDC Provider


    Connect an OpenID Connect identity provider, including Google Workspace.

    Add an OIDC Provider

  • Add a SAML Provider


    Connect a SAML 2.0 identity provider using its metadata URL or file.

    Add a SAML Provider

  • Configure Email & Password Sign-In


    Enable password sign-in with a password policy, lockout rules, and invitations.

    Configure Email & Password Sign-In

  • Invite User


    Invite a new user by email to set up their sign-in credentials.

    Invite User

  • Revoke Invitation


    Cancel a pending invitation before it is used.

    Revoke Invitation

  • Manage Providers


    Test, edit, enable, disable, and delete sign-in providers.

    Manage Providers

  • Review Link Approvals


    Approve or reject requests to link a new sign-in identity to an existing account.

    Review Link Approvals

  • View the Sign-In Log


    Audit sign-in activity and provider configuration changes.

    View the Sign-In Log


API & FAQ

  • API


    Manage sign-in providers programmatically via the Qualytics API.

    API

  • FAQ


    Common questions about providers, linking, and the sign-in experience.

    FAQ