Single sign-on (SSO)

People sign in to Erlangly with their company account, through Microsoft Entra ID, Google Workspace, Okta or any OpenID Connect provider, instead of an Erlangly password. It's in every plan, the free plan included: there's no enterprise tier to buy first.

What you get

  • One company account: the sign-in page offers a “Sign in with…” button for your provider, and people never need an Erlangly password.
  • Require it for staff (admins, planners and supervisors) or for everyone. Once it's required, nobody can sign in with an Erlangly password or reset one.
  • Leavers lose access with their company account. Single sign-on sessions last 12 hours; then Erlangly checks with your provider again, so someone turned off there can't come back. Turning someone's account off under Settings → Users signs them out everywhere at once.
  • Only the people you've invited, with a verified email address in the domains you allow. Guest accounts from other organisations are turned away, and the domain is checked at every sign-in.
  • Never locked out: break-glass admins keep a password for when your provider is down, and each of their password sign-ins is emailed to the other admins. On the server, erlangly sso off stops requiring it.

Before you start

  • Erlangly served over HTTPS: installed with a domain, or behind your own HTTPS proxy. Identity providers only send people back to https:// addresses.
  • Someone who can register an app with your identity provider, usually your IT team.
  • Your people invited to Erlangly with their work email address, their main address at the provider rather than an alias. Signing in doesn't create accounts.

Set it up

  1. In Erlangly, go to Settings → Sign-in and choose your provider. Copy the redirect URI it shows.
  2. In your identity provider, create an app for Erlangly (Microsoft Entra calls it an app registration; Okta and Google, an OIDC web app) with that redirect URI and the openid, email and profile scopes.
  3. Back in Erlangly, fill in its details: Microsoft Entra's tenant ID (on the app registration's Overview page), your Okta address, or another provider's issuer address; the client ID and secret; and the email domains people sign in with.
  4. Test it by signing in with your own account. That shows it works, and links your account so you can always get back in.
  5. Turn it on. The sign-in page now offers it to everyone.
  6. Require it, if you want to: for staff or for everyone, with at least one break-glass admin.

How it keeps sign-in safe

  • OpenID Connect with PKCE. Erlangly checks the provider's signature on every sign-in itself, against the provider's published keys, along with who issued it, who it's for and when it expires.
  • Erlangly only talks to your provider's own addresses, which it finds from the issuer you give it.
  • The client secret is stored encrypted, and every change to sign-in settings is in the audit trail.
  • Everything stays on your server: your provider sends people back to your own install, never through us.

Questions

  • SAML? Not yet. OpenID Connect covers Microsoft Entra ID, Okta, Google Workspace, JumpCloud, Keycloak, Auth0 and AD FS 2016 or later. If you need SAML, tell us.
  • Accounts created from the provider (SCIM)? Not yet: add people in Erlangly, one by one or from a spreadsheet, and invite them. Single sign-on then signs them in.
  • Roles from the provider's groups? Roles are set in Erlangly, under Users.
  • Several providers? One per install.
  • Does it cost extra? No. Every plan has every feature, single sign-on included.