Single sign-on with OIDC
Limrun acts as an OIDC service provider. It uses each user's verified email domain to select the organization's OIDC connection.
Once a domain is verified and its organization has an SSO connection, everyone with that email domain must use Continue with SSO. This applies to new signups and existing accounts. Google, GitHub, Microsoft, and email-code sign-in cannot be used for that domain.
For provider-specific setup, see Okta or Microsoft Entra ID. To manage users and group access, see SCIM provisioning.
Before you start
Before you configure SSO, make sure you have:
- Admin access to the Limrun organization.
- Permission to create an OIDC web application in your identity provider.
- Access to the DNS provider for the email domain your users sign in with.
- An email domain that belongs to the Limrun organization.
Supported features
Limrun supports:
- OIDC authorization code flow
- SP-initiated SSO
- IdP-initiated SSO through OIDC third-party initiated login
- Just-In-Time provisioning
- Single Logout
- Universal Logout through Global Token Revocation
Verify your email domain
Each SSO domain must be verified before users with that domain can sign in through the OIDC connection. Verification needs access to your DNS records; if that is not possible, contact Limrun support for manual verification.
-
Open console.limrun.com.
-
Go to Settings.
-
In Domain Verification, add the email domain that should use SSO.
-
Create the TXT record shown in the verification dialog:
DNS field Value Type TXTHost / Name Copy from Limrun. Value Copy from Limrun. -
After the DNS record is published, click Verify DNS in Limrun.
New domains have auto-join enabled by default. Auto-join takes effect after verification. If you manage domains through the API, set autoJoinEnabled: false to opt out. Without SCIM, successful SSO sign-in adds the user to the connection's organization regardless of this setting. Connecting SCIM disables auto-join and new SSO admission during setup. Once activated, SCIM requires an active provisioned user and a mapped group.
Create the OIDC application
-
In your identity provider, create a new OIDC application.
-
Choose Web Application as the application type.
-
Use the authorization code flow.
-
Make sure the ID token includes the user's
emailclaim. -
Name the app
Limrun. -
Add this sign-in redirect URI:
https://api.limrun.com/authn/oidc/callback -
If your provider asks for an initiate login URI, add:
https://api.limrun.com/authn/oidc/login -
Assign the users or groups that should have access to Limrun.
-
Save the app.
Copy the OIDC values
Copy these values from your identity provider:
| Limrun field | Provider value |
|---|---|
| Issuer URL | The issuer from the provider's OpenID configuration. |
| Client ID | The app's client ID. |
| Client Secret | The app's client secret. |
The issuer URL is the issuer value from your provider's OpenID configuration document. For example, with Okta:
https://your-org.okta.com/.well-known/openid-configurationUse the issuer value from that JSON document:
https://your-org.okta.comSave the connection in Limrun
- Return to console.limrun.com.
- Go to Settings > Single Sign-On.
- Confirm the redirect URI shown in Limrun matches the redirect URI in your identity provider.
- Enter the Issuer URL, Client ID, and Client Secret.
- Click Save.
Limrun discovers the provider from the issuer URL and requests the openid, email, and profile scopes.
Configure Single Logout (optional)
If your identity provider supports OIDC Single Logout, add the Post Logout Redirect URI shown in Limrun to your OIDC application's allowed logout redirect URIs.
For production, this value is:
https://console.limrun.com/authn/loginWhen a user signs out of Limrun, Limrun revokes the user's Limrun token and redirects through the provider's end_session_endpoint when the provider publishes one.
Configure Universal Logout (optional)
If your identity provider supports Global Token Revocation, configure this endpoint:
https://api.limrun.com/authn/oidc/global-token-revocationLimrun accepts these subject identifier formats:
| Format | How Limrun resolves it |
|---|---|
iss_sub | Matches the OIDC issuer and the user's OIDC sub. |
email | Matches the user's email after confirming the domain belongs to the OIDC connection's organization. |
Sign in
For SP-initiated sign-in, users start from the Limrun console:
- Go to console.limrun.com/authn/login.
- Click Continue with SSO.
- Enter your work email address.
- Complete authentication in your identity provider.
If the email domain is verified and the provider sign-in succeeds, Limrun signs the user in and redirects them to the console.
Troubleshooting
Users see "Your organization requires SSO". Choose Continue with SSO and enter the work email address. Users who previously signed in with Google or another method can use the same email through SSO to keep their existing account.
Users see "SSO not configured". Confirm the user's email domain is added under Settings > Domain Verification and shows Verified. Limrun only starts OIDC SSO for verified domains.
The provider rejects the redirect URI. Confirm that the redirect URI is exactly https://api.limrun.com/authn/oidc/callback.
The provider returns an ID token without an email. Configure the OIDC app so the ID token includes the user's email claim. Limrun requires the email claim to match the user to a verified organization domain.
A user authenticates with the provider but cannot enter Limrun. Confirm the user's email domain is verified in Limrun and assigned to the same organization as the OIDC connection.
Limits and account linking
- Limrun supports OIDC SSO. For user and group provisioning, see SCIM provisioning. SAML is not supported.
- A Limrun organization has one OIDC connection.
- Without SCIM, a first SSO sign-in creates an account and joins the organization. With SCIM, provisioning creates the account before sign-in. New users can sign in after activation when they are active in the directory and belong to a group mapped to a Limrun role.
- If a user already exists with the same verified email address, a successful OIDC sign-in links that account to the OIDC identity for the organization.
Was this guide helpful?