Skip to content

Generic OIDC provider

Myra AI Workspace signs users in through any OpenID Connect (OIDC) identity provider that publishes a standard discovery document — Okta, Auth0, Keycloak, Google Workspace, Active Directory Federation Services (ADFS), and others. For Microsoft Entra ID, follow the dedicated Microsoft Entra ID guide, which covers the Entra-specific directory pin and guest policy.

Single sign-on authenticates existing accounts only — provision the users first. Required role: tenant admin or admin (the SSO_MANAGE permission).

Note: The examples use the production admin-API host ai-api-admin.myra.eu. On the integration environment, substitute ai-api-admin-int.myra.eu.


Registering the redirect URI at the provider

Register this exact redirect URI (also called the callback or reply URL) in the provider's application:

https://ai-api-admin.myra.eu/admin/auth/oidc/callback

This is a single, fixed callback URL. It is not tenant-specific — Myra recovers the tenant from the signed login state, not from the URL. The provider does an exact string match on this value, so register it with no trailing slash or extra characters.

Collecting the provider values

From the provider's application, record:

  • The issuer — the base URL that publishes .../.well-known/openid-configuration (for example https://example.okta.com or https://accounts.google.com).
  • The client ID.
  • A client secret.
  • The stable subject claim name. Myra accepts sub or oid. Do not use a mutable claim such as email. Most generic providers (Okta, Auth0, Keycloak, Google Workspace) put the stable identifier in sub.

Request the scopes openid, email, and profile. Grant admin consent at the provider if the provider requires it.

Configuring the OIDC panel in Myra

  1. Open Administration → Tenants.
  2. Select the tenant, then open its edit dialog.
  3. Open the Single sign-on (SSO) section.
  4. Select the Single sign-on (OIDC) enabled checkbox.
  5. In the Issuer URL field, enter the provider's issuer.
    • Myra verifies that the issuer resolves an OIDC discovery document.
  6. In the Client ID field, enter the client ID.
  7. In the Client secret field, paste the client secret.
    • The secret is stored encrypted and never returned. On a later update, leave the field empty to keep the stored secret.
  8. In the Subject claim drop-down list, select sub.
    • The drop-down pre-selects oid, which is correct for Microsoft Entra. For a generic provider that issues the stable identifier in sub, change the selection to sub.
  9. In the Allowed email domains field, enter the comma-separated domains whose users may sign in.
    • This is the verified-domain allowlist. The provider may only sign in users at these domains.
  10. If required, map an identity attribute to Myra groups using the Group attribute and Group mapping fields.
  11. Save the dialog. -> The Single sign-on (OIDC) enabled checkbox stays selected, and the tenant's users can sign in through the provider.

User resolution

At sign-in Myra reads the identity from the token by the claim precedence email → preferred_username → upn. When none of the three is present in an allowed domain, the sign-in is refused. Myra links the identity to the existing account and sets the session.

Token verification

Myra verifies the id_token in-process, fail-closed at every step: RS256 signatures only (keys from the configured jwks_uri); exact issuer match; the audience must contain the client ID; and the login-time nonce must match. For the full verification contract, see Admin API authentication.

PKCE

Interactive OIDC sign-in uses PKCE (RFC 7636, S256) end-to-end. The /start redirect carries the code_challenge, and the token exchange sends the matching code_verifier. PKCE is required for a single-page-application or public app registration and is harmless for a confidential application, so no configuration is needed.