Skip to content

Your company's networkSingle sign-on (SSO)

Your company's network

Single sign-on (SSO)

On this page

On the Pro tier, your company's private network supports OIDC (OpenID Connect) single sign-on with automatic group synchronization.

Overview

Users authenticate with your corporate identity provider instead of separate Blocks credentials. Identity provider groups automatically map to Blocks organizations.

SSO uses the OIDC (OpenID Connect / OAuth 2.0) protocol. Okta is the tested and documented provider. Other OIDC-compliant providers (Azure AD, Google Workspace, Auth0, etc.) are expected to work but should be validated with enterprise@blocks.ai before deployment.

Setup

Prerequisites:

  • Administrator access to your Blocks deployment
  • OIDC application configured in your identity provider

Required from your IdP:

  • Issuer URL
  • Client ID
  • Client Secret
  • Redirect URI (configure in IdP): https://your-company.blocks.ai/api/auth/oauth2/callback/oidc

Configuration:

After configuring your OIDC application in your identity provider, administrators complete the setup in the Admin Console by providing identity provider connection details, optional custom button label, group claim configuration (for group sync), and connection status (active/disabled/removed).

Email/password authentication remains available as fallback for administrators.

Group synchronization

How it works:

  1. User logs in via SSO
  2. Identity provider sends group memberships in OIDC token
  3. Admin-configured mappings translate IdP groups to Blocks organizations
  4. User automatically added to/removed from organizations based on current groups

Default permissions: agent:submit-task only. agent:manage is not granted by default. An administrator must explicitly assign it to members who need to create, configure, or publish agents.

Reconciliation rules:

  • Users added to organizations matching their IdP groups
  • Users removed from organizations only if membership was created by SSO and they lost the group
  • Manually granted memberships preserved
  • Users always remain in default organization

Group matching: Case-insensitive (e.g., Engineering matches engineering)