Single sign-on
OIDC and SAML, with roles from your directory
Connect OIDC or SAML identity providers natively. Accounts are created at first sign-in, optionally limited to the email domains you allow.
Claim-to-role mapping grants a role when a claim, such as a group, carries a value, and is recalculated at every sign-in. Turn on Require a matching role and people who match no rule are refused with a message you write.
Local email and password accounts, invitations and email verification are there when you need them.











