Security & access
Sign-in methods, SSO, portal access, team security, and privacy.
JM
How sign-in worksUnderstand who can get into your portal and how customers and teammates sign in: portal access channels, sign-in methods, team security, sessions, and why widget sign-in never grants admin access.
7 min readSet up magic-link sign-inTurn on passwordless magic-link sign-in in Access & Security, learn how the emailed link works, and what email delivery it needs on Cloud and on a self-hosted instance (SMTP, Amazon SES, or Resend).
2 min readSet up OAuth providersSet up social sign-in with GitHub, Google, Microsoft and 7 more providers: the callback URL for each provider, where to paste credentials in Access & Security, and fixes for common errors.
9 min readSet up single sign-onConnect an OIDC identity provider such as Okta or Entra ID, copy the correct redirect URI, test sign-in, verify domains, require SSO, generate recovery codes, and map roles from claims.
10 min readConfigure team securitySecure how your team signs in: choose sign-in methods, require two-factor authentication, reset a member's 2FA, use recovery codes, and review and export the audit log.
6 min readManage privacy and data handlingWhat data Quackback stores, how secrets and passwords are protected, what is sent to your AI provider, telemetry on self-hosted instances, and how to export or delete a user's data.
7 min readControl portal access and sign-inMake your portal public or private, allow anonymous interaction, admit people by email domain, invite or segment, carry widget sign-in over to the portal, and choose sign-in methods including a custom OIDC button.
9 min read