Integrations
/
OpenID / OIDC
Authentications

Add single sign-on with OpenID/OIDC

Jet Admin integrates with OIDC so you can easily add SSO.
Overview

The Jet Admin OpenID Connect integration lets your app authenticate users against any standards-based identity provider your organization already runs, driven by the same roles and permissions you already manage in Jet. Whether that provider is Okta, Azure AD, a custom identity service or something else entirely, the whole sign-in flow runs through OIDC, and access stays in sync with the provider's own groups and claims.

That covers what teams build with OpenID Connect first: internal tools that need to plug into whatever identity provider IT already standardized on, without a bespoke integration for each one. Because Jet maps claims from the ID token to app roles, a person's permissions update automatically as their provider-side group membership changes.

What you can do
Configure OpenID Connect sign-in
Connect your app's sign-in screen to any OpenID Connect identity provider your organization already runs.
Map claims to user fields
Pull name, email, groups and custom claims from the ID token into your app's own user record.
Assign roles from token claims
Set a user's role and permissions in your app based on the groups or claims their identity provider sends.
Refresh and validate tokens
Keep a session valid across a login by refreshing and validating the ID token behind the scenes.
Use Cases
Scenario
What it looks like
Enterprise SSO rollout
Give employees one-click access to an internal tool through the identity provider your organization already runs.
Multi-provider authentication
Support any standards-based identity provider without building a custom integration for each one.
Automatic role provisioning
Grant the right permissions the moment someone signs in, based on claims their identity provider sends.

Key benefits

  • Works with any OIDC provider. Connect once to a standards-based protocol instead of a specific vendor's API.
  • Automatic role sync. Permissions update from the claims your identity provider sends on every login.
  • Centralized offboarding. Removing someone at the identity provider removes their access to the app.
  • Fewer passwords, less risk. No separate password to phish, forget or reuse.
  • Standards-based security. Tokens are validated and refreshed automatically behind the scenes.

How to connect Jet Admin with OpenID Connect

  1. In your identity provider, register a new OIDC application and note the client ID, client secret and issuer URL.
  2. In Jet Admin, open your app's authentication settings and choose Custom OIDC as the sign-in method.
  3. Enter the client ID, client secret and issuer URL from your provider.
  4. Map the claims you want to use to roles inside your Jet app.
  5. Test sign-in with a user in each claim group to confirm roles apply correctly.
  6. Roll out the login link to your team.