Single Sign-On (SSO) & Identity
Configure enterprise authentication with SAML 2.0, OpenID Connect (OIDC), Google Workspace, Microsoft Entra ID (Azure AD), and Okta.
Overview
Thrico provides enterprise Single Sign-On (SSO) allowing your community members and administrators to log in using their corporate identity provider (IdP). SSO eliminates password fatigue, centralizes access control, and enforces your organization's multi-factor authentication (MFA) policies.
Supported Identity Providers
| Identity Provider | Protocol | JIT (Just-In-Time) Provisioning | Group / Role Mapping |
|---|---|---|---|
| Google Workspace | OAuth 2.0 / OIDC | Yes | Domain & Org Unit |
| Microsoft Entra ID (Azure AD) | SAML 2.0 / OIDC | Yes | Security Groups |
| Okta | SAML 2.0 / OIDC | Yes | Okta Groups |
| Custom SAML 2.0 | SAML 2.0 | Yes | Custom Attributes |
| Custom OIDC | OpenID Connect | Yes | JWT Claims |
Setting Up SSO
Google Workspace (OAuth / OIDC)
- Open the Google Cloud Console.
- Create an OAuth 2.0 Client ID under APIs & Services → Credentials.
- Application Type: Web application.
- Authorized Redirect URI:
- In Thrico Dashboard → Settings → Security → SSO:
- Paste Client ID and Client Secret.
- Specify allowed domains (e.g.
yourcompany.com).
Just-In-Time (JIT) Provisioning
When JIT is enabled, users who authenticate successfully through your IdP for the first time will automatically have an account created in Thrico with their profile information mapped directly from the SAML assertions or OIDC ID Token claims.