OIDC Single Sign-On
ManyLayers supports OIDC-based SSO for both API key authentication and workspace login. Connect your existing identity provider — Okta, Azure AD, Google, Keycloak, or any OIDC-compliant IdP.Configuration
Authentication order
ManyLayers evaluates authentication in this order:- API key —
Authorization: Bearer ml-...prefixed keys - OIDC JWT —
Authorization: Bearer <jwt>validated against your configured issuer - Session cookie — workspace browser sessions
- Personal Access Token —
Authorization: Bearer ml_pat_...tokens
SSO login flow
- Your users click “Sign in with SSO” in the workspace UI
- The UI redirects to your OIDC provider with the configured
spa_client_id - After authentication, the provider redirects back with an authorization code
- The UI calls
POST /auth/ssowith the OIDC token - ManyLayers validates the token, auto-provisions the user, and returns a session
Team and role mapping
Theteam_claim and role_claim extract team membership and role from the JWT. The team_mapping maps your IdP group names to gateway teams. Users with the admin_role value get full admin access.
SCIM 2.0 User Provisioning
SCIM enables automated user lifecycle management — provision new users and deactivate departing ones directly from your IdP without manual administration.Supported operations
| Resource | Operations | Notes |
|---|---|---|
/scim/v2/Users | Full CRUD | Maps userName to email, active to enabled status |
/scim/v2/Groups | GET only | Returns empty list; write operations return 501 |
SCIM authentication
SCIM endpoints use a Bearer token that is org-scoped and managed by org admins:| Endpoint | Auth | Description |
|---|---|---|
GET /org/scim/token | org_admin | Get the current SCIM token |
POST /org/scim/token | org_admin | Rotate the SCIM token |
SCIM endpoints
| Method | Path | Description |
|---|---|---|
GET | /scim/v2/Users | List users (supports filter, startIndex, count) |
POST | /scim/v2/Users | Create a user |
GET | /scim/v2/Users/{id} | Get a user |
PUT | /scim/v2/Users/{id} | Replace a user |
PATCH | /scim/v2/Users/{id} | Partial update (e.g. deactivate) |
DELETE | /scim/v2/Users/{id} | Deactivate a user |
Example: provision a user
Content-Type: application/scim+json.
Next steps
- Set up teams and roles that your IdP groups will map to
- Create API keys for programmatic access
- Review plans and quotas