OIDC single sign-on
Users sign in through your identity provider and exist from first login.
WhereConsole
Introduced Mar 13, 2026
your IdP→OIDC sign-in→user exists, first login→deprovision there ✓ gone here
How it works
Sign in with what you already have.
OIDC against your identity provider — no passwords living on this platform.
Users exist from first login.
No separate user database to keep in step, no accounts to pre-provision.
Deprovision once.
Removing someone at the IdP removes their access here too.
See it on your own cluster.
Thirty minutes, your infrastructure, your stack. Or skip the call — it is one Helm release onto a cluster you already run.