Thrico Logo

Single Sign-On (SSO) & Identity

Configure enterprise authentication with SAML 2.0, OpenID Connect (OIDC), Google Workspace, Microsoft Entra ID (Azure AD), and Okta.

Overview

Thrico provides enterprise Single Sign-On (SSO) allowing your community members and administrators to log in using their corporate identity provider (IdP). SSO eliminates password fatigue, centralizes access control, and enforces your organization's multi-factor authentication (MFA) policies.


Supported Identity Providers

Identity ProviderProtocolJIT (Just-In-Time) ProvisioningGroup / Role Mapping
Google WorkspaceOAuth 2.0 / OIDCYesDomain & Org Unit
Microsoft Entra ID (Azure AD)SAML 2.0 / OIDCYesSecurity Groups
OktaSAML 2.0 / OIDCYesOkta Groups
Custom SAML 2.0SAML 2.0YesCustom Attributes
Custom OIDCOpenID ConnectYesJWT Claims

Setting Up SSO

Google Workspace (OAuth / OIDC)

  1. Open the Google Cloud Console.
  2. Create an OAuth 2.0 Client ID under APIs & Services → Credentials.
  3. Application Type: Web application.
  4. Authorized Redirect URI:
    https://api.yourdomain.com/auth/sso/google/callback
  5. In Thrico Dashboard → Settings → Security → SSO:
    • Paste Client ID and Client Secret.
    • Specify allowed domains (e.g. yourcompany.com).

Just-In-Time (JIT) Provisioning

When JIT is enabled, users who authenticate successfully through your IdP for the first time will automatically have an account created in Thrico with their profile information mapped directly from the SAML assertions or OIDC ID Token claims.


Next Steps

On this page