OpenID Connect connects any issuer that publishes a discovery document. The form is the same OIDC connection Microsoft Entra ID and BeyondTrust use. Authdog routes users by email domain.
Open the connection
In the Authdog console:
- Select the project and environment.
- Open Authentication > Providers with the Enterprise filter.
- Choose OpenID Connect.
- Copy the redirect / callback URL Authdog displays and register it on the issuer as a web redirect URI.
Configure the issuer
| Field | Value |
|---|---|
| Connection name | A name that shows in the Configured list |
| Connection Mode | External (Remote provider) for an issuer you do not run as an Authdog OIDC client |
| OpenID Connect Discovery URL | The URL of the discovery document, not a bare issuer that does not serve it |
| Client ID | The client registered at the issuer |
| Authentication Method | Client Secret, unless the issuer requires Private Key JWT |
| Client secret | Stored encrypted. Leave blank on a later edit to keep the stored secret |
For Private Key JWT, provide the Private Key (PEM) and Signing Algorithm (RS256, RS384, or RS512) instead of a client secret.
Internal (Select OIDC Client) uses an OIDC client already registered in this environment. Pick that client in OIDC Client and skip the discovery URL.
Scopes default to openid profile email. Add an extra scope only when a claim you need requires it. Leave Prompt on the issuer default unless you need an account picker or a forced re-authentication.
Route by email domain
In Email domains (for SSO discovery):
acme.comThe entry matches that domain and its subdomains. Keep domains from overlapping other enterprise connections in the same environment. Only active connections participate in discovery.
Test it
- Use Test on the connection.
- Sign in with a user in the routed domain and confirm the subject and email claims.
- Repeat in production. If you add a custom domain, update the redirect URI on the issuer with the URL shown in the form.
Named vendors with the same form: Microsoft Entra ID and BeyondTrust.
Related
| Read | To learn how to |
|---|---|
| Enterprise SSO | Discovery, domain routing, and secrets |
| SAML 2.0 | When the IdP speaks SAML instead of OIDC |
| Marketplace | The listing for this integration |