Generic OIDC provider
Myra AI Workspace signs users in through any OpenID Connect (OIDC) identity provider that publishes a standard discovery document — Okta, Auth0, Keycloak, Google Workspace, Active Directory Federation Services (ADFS), and others. For Microsoft Entra ID, follow the dedicated Microsoft Entra ID guide, which covers the Entra-specific directory pin and guest policy.
Single sign-on authenticates existing accounts only — provision the users first. Required role:
tenant admin or admin (the SSO_MANAGE permission).
Note: The examples use the production admin-API host
ai-api-admin.myra.eu. On the integration environment, substituteai-api-admin-int.myra.eu.
Registering the redirect URI at the provider
Register this exact redirect URI (also called the callback or reply URL) in the provider's application:
This is a single, fixed callback URL. It is not tenant-specific — Myra recovers the tenant from the signed login state, not from the URL. The provider does an exact string match on this value, so register it with no trailing slash or extra characters.
Collecting the provider values
From the provider's application, record:
- The issuer — the base URL that publishes
.../.well-known/openid-configuration(for examplehttps://example.okta.comorhttps://accounts.google.com). - The client ID.
- A client secret.
- The stable subject claim name. Myra accepts
suboroid. Do not use a mutable claim such asemail. Most generic providers (Okta, Auth0, Keycloak, Google Workspace) put the stable identifier insub.
Request the scopes openid, email, and profile. Grant admin consent at the provider if the
provider requires it.
Configuring the OIDC panel in Myra
- Open Administration → Tenants.
- Select the tenant, then open its edit dialog.
- Open the Single sign-on (SSO) section.
- Select the Single sign-on (OIDC) enabled checkbox.
- In the Issuer URL field, enter the provider's issuer.
- Myra verifies that the issuer resolves an OIDC discovery document.
- In the Client ID field, enter the client ID.
- In the Client secret field, paste the client secret.
- The secret is stored encrypted and never returned. On a later update, leave the field empty to keep the stored secret.
- In the Subject claim drop-down list, select sub.
- The drop-down pre-selects oid, which is correct for Microsoft Entra. For a generic provider
that issues the stable identifier in
sub, change the selection to sub.
- The drop-down pre-selects oid, which is correct for Microsoft Entra. For a generic provider
that issues the stable identifier in
- In the Allowed email domains field, enter the comma-separated domains whose users may sign in.
- This is the verified-domain allowlist. The provider may only sign in users at these domains.
- If required, map an identity attribute to Myra groups using the Group attribute and Group mapping fields.
- Save the dialog. -> The Single sign-on (OIDC) enabled checkbox stays selected, and the tenant's users can sign in through the provider.
User resolution
At sign-in Myra reads the identity from the token by the claim precedence email →
preferred_username → upn. When none of the three is present in an allowed domain, the sign-in
is refused. Myra links the identity to the existing account and sets the session.
Token verification
Myra verifies the id_token in-process, fail-closed at every step: RS256 signatures only (keys from
the configured jwks_uri); exact issuer match; the audience must contain the client ID; and the
login-time nonce must match. For the full verification contract, see
Admin API authentication.
PKCE
Interactive OIDC sign-in uses PKCE (RFC 7636, S256) end-to-end. The /start redirect carries the
code_challenge, and the token exchange sends the matching code_verifier. PKCE is required for a
single-page-application or public app registration and is harmless for a confidential application, so
no configuration is needed.