Changelog

Single sign-on improvements

SSO setup is now a three-step flow: connect, test, enable. It also supports identity providers that don't send an email address.

Setup

  • Three steps: connect a provider, run a test sign-in, then enable it
  • Advanced options folded away until needed
  • Editable scopes, checked against what the provider says it supports
  • Choice of the sign-in prompt the provider shows
  • Table of the claims the provider returned during the test
  • Claim mapping to roles and to person attributes that can drive segments
  • Custom provider icons, and the provider's profile picture as the avatar

Provider compatibility

  • Providers that don't share an email address, with people asked for a contact address instead
  • Providers that keep identity details in the access token
  • Existing providers keep working without a change to their redirect address

Fixes

  • Sign-in alert emails only go out for genuinely new devices
  • Signing out of Quackback no longer signs you out of your identity provider
  • Providers that leave out a standard security value in their sign-in response are now detected

Availability: Settings > Access & Security > SSO.

Shipped Features