Documentation
Set up single sign-on
Enterprise organizations configure single sign-on themselves in the dashboard, with OIDC or SAML. An organization uses one protocol at a time. Changes need the organization owner and a sign-in from the last 10 minutes.
OIDC
- In your identity provider, create an application and register this redirect URI:
https://ovyero.visnryentertainment.com/api/v1/auth/sso/callback - In the dashboard open Settings → Security & access and enter the Issuer URL (must be
https://), the Client ID, the Client Secret and your allowed email domains. Save. - Run Test connection, then Enable. Saving alone never turns SSO on.
- The client secret is write-only: it is never shown back.
- Allowed domains are a hard boundary on who may sign in. Wildcards are not accepted, and a public email provider (for example gmail.com) needs an explicit confirmation.
- Sign-in starts at
https://ovyero.visnryentertainment.com/api/v1/auth/sso/start?tenant=<your organization id>.
SAML
- Give your identity provider the service-provider values shown on the SAML card in Settings: the ACS URL
https://ovyero.visnryentertainment.com/api/v1/auth/saml/acsand the metadata URLhttps://ovyero.visnryentertainment.com/api/v1/auth/saml/metadata?tenant=<your organization id>. - Enter your provider’s entity ID, sign-in URL (must be
https://) and signing certificate (the PEM block that starts-----BEGIN CERTIFICATE-----), plus at least one allowed email domain. Save. - Run a test sign-in. SAML can be enabled only after a real signed assertion from your provider has been verified.
- Enable.
Require single sign-on
The owner can require SSO for the organization. Set up and test your provider first. While the requirement is on, SSO cannot be disabled: turn off “Require single sign-on” before disabling the provider, otherwise everyone would be locked out.
Troubleshooting
- “Not enabled for your account yet”: self-serve configuration is not switched on for your organization. Contact us.
- “This change needs a fresh sign-in”: request a new sign-in link and retry within 10 minutes.
- OIDC and SAML both configured: disable one before enabling the other.
More: Troubleshooting.