This article covers the Single Sign-On Configuration page. If you are not familiar with SAML or OIDC, start with SAML SSO or OpenID Connect; this article assumes you know which protocol you are using and have access to your identity provider (IdP).
Admin access to your site
Gather the following from your IdP before you start:
For SAML:
For OIDC:
SAML SSO and OpenID Connect have a full description of each field.
The new service appears in the list immediately, whether it is set to Active or Inactive.
Most IdPs publish an OpenID discovery document, typically at a .well-known/openid-configuration URL. If yours does, you can skip entering each endpoint by hand:
This also works with providers that use non-standard discovery paths, including AWS Cognito user pools. You will still need to enter Client ID and Client Secret by hand, since neither is part of the discovery document.
A confirmation message appears once your changes are saved.
Secret and certificate fields (Client Secret, X.509 certificate, JWKS document) never show their stored value, and leaving one blank does not clear it.
The placeholder tells you which case you are in: "Enter a new value" means nothing is stored yet, and "Enter new value to replace existing" means a value is already configured and you can leave the field blank to keep it.
Description is required for both SAML and OIDC services. SAML also requires an Entity ID, Single Sign-On URL, and X.509 certificate. OIDC requires Client ID, Issuer, Authorize URL, Token URL, and at least one of JWKS URL or JWKS document.
If a save fails, the error appears inline on the form so you can fix it and resubmit. Your other field values persist and the form does not reset.
Setting a service to Inactive removes it from the sign-in page. Users will not see it as a sign-in option, but the configuration is preserved and you can reactivate it later.
Both Active and Inactive services stay listed on the Single Sign-On Configuration page.