-
-
Notifications
You must be signed in to change notification settings - Fork 1
Home
Sign in to Jellyfin through OpenID Connect or SAML 2.0 identity providers.
Status: this is an actively-developed, security-first revival of the archived 9p4/jellyfin-plugin-sso. This wiki grows with the plugin — pages describe what is actually implemented today, not planned features. If something here disagrees with the code, the code wins; please open an issue.
- Installation — build from source and install into Jellyfin.
- Security Model — how the login path fails closed.
-
Provider setup — see
providers.mdin the repo (per-IdP guides). - Troubleshooting.
- OpenID Connect and SAML 2.0 sign-in, multiple providers side by side.
- Role-based access: login, administrator, library folders, Live TV.
- A fail-closed login path (see Security Model).
- Avatar sync, Quick Connect support, self-service account linking (
/SSOViews/linking).
Report vulnerabilities privately via the repository's Report a vulnerability form — not the public issue tracker.
Repository · Issues · Releases · Security policy - report vulnerabilities privately, never in a public issue. Pages describe what is implemented today; if the wiki disagrees with the code, the code wins.
Getting started
- Installation
- Provider Setup
- Hardening & Options Reference
- Migrating from 9p4
- Troubleshooting
- Rollback
How it works
Security
- Security Model
- Security Conformance (ASVS / RFC 9700)
- SSO-Only Login - design record
- Single Logout - design record
Standards & process (internal / maintainer)