Skip to content

Single sign-on

OpenID Connect

Connect any identity provider that supports OpenID Connect (OIDC) to SurrealDB. Use this connection when your provider is not listed by name. You register a web application in your identity provider, then enter its details in a new connection in SurrealDB Studio.

Before you start, verify the email domain your company uses.

  1. In your identity provider, register a web application that uses the authorization code flow and has a client secret.

  2. Add https://auth.surrealdb.com/login/callback as a redirect URI. Some providers call it a callback URL or a sign-in redirect URI.

  3. Make sure the ID token includes each person's email address and name. Most providers include them when the email and profile scopes are requested.

  4. Copy the client ID and the client secret.

You also need the provider's discovery URL. It ends in /.well-known/openid-configuration, for example https://idp.example.com/.well-known/openid-configuration. SurrealDB reads the provider's endpoints and signing keys from it.

  1. Open Single sign-on in your enterprise and add a new connection.

  2. Select OpenID Connect.

  3. Under Name the connection, enter a Display name. Members see this name on the sign-in screen.

  4. Under Enter the OpenID Connect details, enter:

    • Discovery URL: the provider's discovery URL from step 1.

    • Client ID: the client ID from step 1.

    • Scopes: optional. Leave it empty to request openid profile email.

    • Client secret: the client secret from step 1.

  5. Under Route sign-in domains, select the verified domains to send to this connection. This is optional, and you can change it later.

  6. Select Create connection.

The Set up OpenID Connect section of the form shows the redirect URI, with a copy button beside it, if you need it again. SurrealDB stores the client secret securely and does not show it again.

If you did not route a domain when you created the connection, route one now. Then choose the applications that people can sign in to with this connection.

Was this page helpful?