Single sign-on

Sign in with the identity provider you already run.

Register the app at your provider

SettingValue
Redirect URIhttps://auth.nyxie.io/api/auth/sso/callback
Scopesopenid email profile
FlowAuthorization code with a client secret

Microsoft Entra ID: App registrations, New registration, web platform, add the redirect URI, create a client secret. Use organizations as the tenant to accept any work account or your tenant ID to restrict it.
Google Workspace: Google Cloud console, Credentials, OAuth client ID, web application, add the redirect URI.
Other OpenID Connect: any issuer that publishes /.well-known/openid-configuration and signs tokens with RS256.

Configure Nyxie

Account settings, Security, Single sign-on. Choose the provider, paste the client ID and secret, list your email domains, pick the role new people get, then Test sign-in. Only after a successful test turn on Require SSO, which refuses password sign-in for those domains.

What happens at sign-in

People type their work email on the sign-in page. If the domain has SSO, the password box disappears and Sign in with SSO sends them to the provider. Nyxie verifies the returned token, matches or creates the user, and signs them in. The provider handles multi-factor; Nyxie does not ask for a second code.

Questions: hello@nyxie.io. Nyxie. All glows well!