-
Notifications
You must be signed in to change notification settings - Fork 0
Auth Enterprise
github-actions[bot] edited this page Sep 4, 2026
·
1 revision
MFA enforcement (TOTP + WebAuthn policy) and SSO via SAML 2.0 and OIDC for Google Workspace, Okta, and Microsoft Entra ID. Free — MIT licensed.
nself plugin install auth-enterpriseNo license key required.
MFA enforcement (TOTP + WebAuthn policy) and SSO via SAML 2.0 and OIDC for Google Workspace, Okta, and Microsoft Entra ID.
Category: authentication. Current version: 1.1.2.
| Env Var | Default | Description |
|---|---|---|
NSELF_SSO |
false |
Enable SSO (SAML 2.0 + OIDC). Set to 'true' to activate. |
AUTH_ENTERPRISE_TOTP_ISSUER |
nSelf |
TOTP issuer name shown in authenticator apps (e.g. 'My Company'). Defaults to 'nSelf'. |
AUTH_ENTERPRISE_SSO_SP_ENTITY_ID |
- |
SAML SP entity ID (URI). Required when NSELF_SSO=true and SAML providers are configured. |
AUTH_ENTERPRISE_SSO_ACS_URL |
- |
SAML Assertion Consumer Service (ACS) URL. Required when NSELF_SSO=true and SAML providers are configured. |
AUTH_ENTERPRISE_SSO_OIDC_CALLBACK_URL |
- |
OIDC redirect URI registered with your IdP. Required when NSELF_SSO=true and OIDC providers are configured. |
| Port | Purpose |
|---|---|
| 3826 | Auth Enterprise service port |
6 table(s) added to your Postgres database:
np_mfa_enrollmentsnp_mfa_recovery_codesnp_mfa_policiesnp_sso_providersnp_sso_sessionsnp_sso_state_cache
GET /health
GET /auth/mfa/policy
PUT /auth/mfa/policy
POST /auth/mfa/recovery
GET /auth/mfa/recovery/codes
POST /auth/mfa/recovery/regenerate
GET /auth/mfa/status
POST /auth/mfa/totp/challenge
POST /auth/mfa/totp/setup
POST /auth/mfa/totp/verify
GET /auth/sso/metadata
GET /auth/sso/oidc/callback
curl http://localhost:3826/healthManifest: plugins/auth-enterprise/plugin.json
- Plugin-Marketplace — full plugin index
- Plugin-Development — write your own plugin
← Home →
- Commands
- File Processing Commands
- GitHub Commands
- ID.me Commands
- Jobs Commands
- Notifications Commands
- Realtime Commands
- Shopify Commands
- Stripe Commands
View All: Home (or see the full alphabetical list below — 129/129 synced with registry.json)
- Access-Controls
- Admin-Api
- AI-CLI
- AI-Studio
- Alerts
- Analytics
- API
- Audit
- Audit-Analytics
- Audit-Log
- Auth-Enterprise
- Backup
- BYOK
- CDC
- CDN
- CI
- Claw-CLI
- Cloudflare
- Compliance
- Content-Acquisition
- Content-Progress
- Content-Safety
- Costs
- CRDT
- Cron
- DDNS
- Devices
- DLQ
- Documents
- Dogfood
- Donorbox
- DR
- E2EE
- Encryption
- Entitlements
- Event-Bus
- Family-Ancestry
- Family-FamilySearch
- Family-GEDCOM
- Family-MyHeritage
- Family-WikiTree
- Feature-Flags
- Federation
- File-Processing
- Flags
- Forgejo
- Functions-V8
- Game-Metadata
- Gateway
- Gauth
- GDPR
- Geocoding
- GitHub
- GitHub-Runner
- HIPAA
- Home
- IDme
- Infra
- Invitations
- Job-Queue
- Jobs
- K8s
- Link-Preview
- Maintenance
- MDNS
- Media-Processing
- Meetings
- MLflow
- Model
- Monitor
- Monitoring
- Notifications
- Notify
- nSelf-Cloud
- nSelf-Eval-Gate
- nSelf-Geo
- nSelf-Image
- nSelf-PDF
- nSelf-Scan
- nSelf-Sync
- nSelf-Vault
- Object-Storage
- Observability
- Ollama
- Payments
- PayPal
- Pentest
- Pentest-Kit
- Plugin-ClawDE
- Plugin-Gauth
- Plugin-LLM-Gateway
- Plugin-PTY
- Plugin-Retrieval
- Podcast
- Post
- Push
- Queue
- Region
- Release
- Retro-Gaming
- Rom-Discovery
- Search
- Sentry-CLI
- Shared-Utils
- Shopify
- SIEM
- SMS
- Soak
- Sports
- Storage
- Storage-Transform
- Stripe
- Subtitle-Manager
- Tenant
- Tenant-Controller
- TMDB
- Tokens
- Torrent-Manager
- Transactional-Email
- VPN
- WAF
- Warehouse
- Watchdog
- Web3
- Webhooks
- Workflows
Related