Identity and access
Single sign-on with OIDC
Sign in with Okta, Entra ID, Authentik, Keycloak or AD FS, with accounts and groups kept in step with your directory.
What it is
People sign in through your existing OpenID Connect provider, such as Okta, Entra ID, Authentik, Keycloak or AD FS. Accounts are created at first sign-in and group memberships refresh from the token on every sign-in.
Why you want it
IT does not want another password store or a shared API key passed around in chat. With SSO, access to AI follows the same joiner, mover and leaver process as every other system.
How it works
- Authorization Code flow with PKCE, nonce and single-use state
- ID tokens verified against the provider's JWKS; RS256/384/512 and ES256/384/512 accepted, EdDSA and 'none' refused
- Groups read from a configurable claim (JANUS_OIDC_GROUPS_CLAIM, default groups); memberOf-style DNs normalized
- /readyz tolerates a brief IdP blip: two failed probe rounds before a replica goes unready
See it on your own network.
The Community edition is free for up to 25 people. The 30-day Business trial unlocks every Business feature.