Skip to main content

Identity Providers

Identity providers enable SSO (Single Sign-On) login through external services like Google, Microsoft, or your own OAuth server. Users can log in with their existing credentials instead of creating a new password.

Supported Providers

  • OAuth 2.0 - Any OAuth 2.0-compliant provider
  • OpenID Connect - For enhanced identity verification
  • SAML - Enterprise single sign-on (coming soon)

How SSO Works

1. User clicks "Login with [Provider]"
2. Redirects to provider's login page
3. User authenticates with provider
4. Provider redirects back with a token
5. Your app calls /auth/federate with the token
6. Backstage returns access and refresh tokens

Configuration

Each provider needs OAuth credentials (client ID and secret) and configuration for allowed redirect URLs and scopes.

Operations