Single sign-on (SSO)

Let your team sign in through your OIDC identity provider with just-in-time membership.

SSO lets members of your team sign in to Gheima through your own OpenID Connect (OIDC) identity provider — Okta, Microsoft Entra, Google Workspace, Keycloak, or any OIDC-compliant IdP. When someone authenticates at your IdP with an email on your claimed domain, they are provisioned into your account just-in-time as a member.

#

  1. 1

    Add a connection

    Enter your OIDC issuer URL and the client ID + secret from an application you register at your IdP. Use the redirect URL https://gheima.ma/api/sso/callback.

  2. 2

    Publish the DNS record

    We generate a TXT record at _gheima-sso.<your-domain>. Add it at your DNS host to prove ownership of the domain.

  3. 3

    Verify

    Once the record is live, verify the connection. It becomes active and your SSO login URL starts working.

#

Members open your SSO login URL and are redirected to your identity provider. After they authenticate, Gheima verifies the returned ID token, confirms the email is on your claimed domain, and creates a session. First-time users are added to your account as members automatically.

curl https://gheima.ma/api/v1/sso/connections \
  -H "Authorization: Bearer $GHEIMA_TOKEN" \
  -d '{"emailDomain":"acme.com","issuer":"https://login.acme.com","clientId":"gheima","clientSecret":"…"}'

Only OIDC providers are supported. The client secret is encrypted at rest and never returned by the API. New members count against your plan’s member limit.

Your team signs in with your identity provider, and new members are provisioned automatically.