Changelog

Unified sign-in and SSO for portal users

A single sign-in dialog now serves both the public portal and the admin area. Workspace SSO also extends to portal users whose email is on one of your verified domains.

Sign-in

  • One sign-in dialog for the portal and the admin, replacing the separate login and signup pages
  • "Admin area" link in the portal user menu for teammates
  • SSO-only workspaces send everyone straight to the identity provider
  • Email field hidden on portal sign-in when only social or SSO sign-in is offered

SSO

  • Workspace SSO for portal users on your verified domains
  • Test sign-in for each provider before you enforce SSO
  • Role mapping from a value your identity provider sends, including groups, roles and nested values, with suggestions from your last test sign-in
  • One default role for new SSO users
  • Recovery codes as a way back in when SSO is enforced
  • Support for identity providers that require PKCE (OAuth 2.1)

Improvements

  • Invite links last 30 days and stop working as soon as an invite is cancelled

Fixes

  • No "Log in" flash right after signing in
  • Correct callback address shown during OIDC setup
  • Settings switches keep their state after saving

Availability: Settings > Access & Security.