{"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"sso","__idx":0},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["sso"]}]},{"$$mdtype":"Tag","name":"ConfigOptionRequirements","attributes":{"products":["Redoc","Revel","Reef","Realm"],"plans":["Enterprise","Enterprise+"]},"children":[]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Restrict project login to specific identity provider categories defined in Reunite."," ","This configuration determines which IdPs are available for logging in to a project."," ","Configuring SSO by itself does not require users to log in to access a project."," ","To require login to a project, ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"/docs/realm/config/access/rbac"},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["rbac"]}]}," or ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"/docs/realm/config/access/requires-login"},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["requiresLogin"]}]}," must also be configured."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"options","__idx":1},"children":["Options"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Option"},"children":["Option"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Type"},"children":["Type"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Description"},"children":["Description"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["sso"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["[string]"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["List of identity provider categories from Reunite."," ","Possible values: ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["REDOCLY"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["CORPORATE"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["GUEST"]},", or ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["[]"]},"."," ","A category corresponds to the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Login type"]}," assigned to an identity provider in Reunite."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["To target a specific identity provider by its unique ID, use ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"/docs/realm/config/access/idps"},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["access.idps"]}]}," instead of ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["sso"]},"."," ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["access.sso"]}," and ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["access.idps"]}," are mutually exclusive and cannot be configured together."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Default value: ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["AUTO"]}," - used when neither ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["sso"]}," nor ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["idps"]}," is defined."," ","It offers ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["GUEST"]}," IdPs, if any are defined in Reunite."," ","Otherwise, it offers ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["CORPORATE"]}," IdPs, if defined in Reunite."," ","When a category contains a single IdP, users are redirected to this IdP."," ","With multiple IdPs, users choose one on the login screen."," ","If no IdPs are defined, it falls back to the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["REDOCLY"]}," IdP."," ","Users then have the option to log in using their Redocly credentials or Social Login providers (like ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Google"]},")."]}]}]}]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"examples","__idx":2},"children":["Examples"]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"use-the-access-object-recommended","__idx":3},"children":["Use the access object (recommended)"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The recommended way to configure ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["sso"]}," is within the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["access"]}," object:"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"yaml","data-title":"redocly.yaml","header":{"title":"redocly.yaml","controls":{"copy":{}}},"source":"access:\n  sso:\n    - GUEST\n    - REDOCLY\n","lang":"yaml"},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"disable-sso","__idx":4},"children":["Disable SSO"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The following example disables SSO using the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["access"]}," object:"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"yaml","data-title":"redocly.yaml","header":{"title":"redocly.yaml","controls":{"copy":{}}},"source":"access:\n  sso: []\n","lang":"yaml"},"children":[]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["You might apply this configuration to a project that also has ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["rbac"]}," configured."," ","In that case, pages assigned to the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["authenticated"]}," default team are not accessible to anyone."," ","Otherwise, if you do not have ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["rbac"]}," configured, or you have all pages assigned to the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["anonymous"]}," default team, all pages are accessible."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"root-level-configuration-deprecated","__idx":5},"children":["Root-level configuration (deprecated)"]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"warning","name":"Deprecated configuration"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Root-level ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["sso"]}," configuration displays warnings when the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["access"]}," object is present."," ","Migrate to the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["access"]}," object format."]}]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"yaml","data-title":"redocly.yaml","header":{"title":"redocly.yaml","controls":{"copy":{}}},"source":"sso:\n  - GUEST\n  - REDOCLY\n","lang":"yaml"},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"resources","__idx":6},"children":["Resources"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":[{"$$mdtype":"Tag","name":"Link","attributes":{"href":"/docs/realm/config/access"},"children":["Access configuration"]}]}," - Group authentication and access settings together using the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["access"]}," object"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":[{"$$mdtype":"Tag","name":"Link","attributes":{"href":"/docs/realm/config/access/rbac"},"children":["RBAC configuration"]}]}," - Complete options for configuring role-based access control for granular project permissions and user management"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":[{"$$mdtype":"Tag","name":"Link","attributes":{"href":"/docs/realm/config/access/requires-login"},"children":["RequiresLogin configuration"]}]}," - Require login for all users to your project without implementing complex role-based access control"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":[{"$$mdtype":"Tag","name":"Link","attributes":{"href":"/docs/realm/reunite/organization/sso/configure-google-sso"},"children":["Configure Google Workspace as a SAML SSO"]}]}," - Integrate Google Workspace SAML 2 SSO with Reunite for enterprise authentication workflows"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":[{"$$mdtype":"Tag","name":"Link","attributes":{"href":"/docs/realm/reunite/organization/sso/sso"},"children":["Single sign-on and login"]}]}," - Understand different identity provider categories in Reunite and how they apply to project authentication"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":[{"$$mdtype":"Tag","name":"Link","attributes":{"href":"/docs/realm/reunite/organization/sso/add-idp"},"children":["Add identity providers"]}]}," - Follow steps to add identity providers in Reunite for centralized authentication management"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":[{"$$mdtype":"Tag","name":"Link","attributes":{"href":"/docs/realm/reunite/organization/sso/configure-sso"},"children":["Configure project SSO"]}]}," - Enable multiple identity provider categories to give users flexible authentication options for your projects"]}]}]},"frontmatter":{"products":["Redoc","Revel","Reef","Realm"],"plans":["Enterprise","Enterprise+"],"description":"Restrict project login to specific identity provider categories defined in Reunite."},"tagList":["admonition","configOptionRequirements","table"],"title":"sso","lastModified":"2026-10-01T23:00:57.000Z"}