Skip to content

History / Enterprise SSO and SCIM

Revisions

  • Document the identity plane the wiki never mentioned Enterprise SSO, SCIM provisioning, and passkeys existed only in SECURITY.md — the wiki had zero occurrences of SCIM or passkey, and its one "Single Sign-On" section described the internal cross-app bridge, so a reader searching for SSO concluded there was no IdP federation. Adds an Enterprise SSO & SCIM page: the link-only provisioning rule, what is and isn't supported, the sequenced enablement with its two restarts, the Okta two-app setup, the joiner/leaver verification, and the control story for a security review. Okta is named as validated; Entra is not. Splits the Authentication page's SSO section into login methods, passkeys and MFA, enterprise OIDC, and the cross-app bridge — with the two senses of the word called out where they were being conflated. Records the SSO secret keys and identity flags in the Bootstrap Guide, and adds identity lifecycle to the built-in controls.

    @jfrench9 jfrench9 committed Aug 24, 2026