Single sign-on

Let members sign in to Proliferate Cloud through your OIDC identity provider.

Organization SSO lets members sign in to Proliferate Cloud through your identity provider, alongside GitHub sign-in.

Proliferate Cloud speaks OIDC (OpenID Connect), so it works with any compliant provider, including Google, Okta, Microsoft Entra ID, Auth0, GitLab, and others. The settings screen shows and manages a single SSO connection per organization, scoped to one or more allowed email domains.

Invite-first. Connections created from the settings screen have just-in-time provisioning turned off, so the normal Cloud flow is to invite a person to the organization first (Members & roles); they can then sign in through SSO. Enabling SSO adds a sign-in path — it does not force members to use it and does not replace GitHub sign-in.

Auth paths

PathUse it when
GitHub sign-inThe default sign-in for Proliferate Cloud. Most teams start here.
Organization SSO (OIDC)You want an org-level sign-in tied to your identity provider and email domains, on top of GitHub sign-in.
Self-hosted authYour org runs a self-hosted deployment and configures its own login backend (GitHub OAuth, Google OAuth, email + password, or OIDC SSO).
Info:

SCIM directory sync (automated user provisioning and deprovisioning) is not available yet.

For provider-specific setup, see the guides for Google, Okta, Microsoft Entra ID, Auth0, and GitLab.

On this page