<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Custom Identity Providers on</title><link>https://deploy-preview-3716--ornate-narwhal-088216.netlify.app/platform/administration/custom-idps/</link><description>Recent content in Custom Identity Providers on</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>Copyright (c) 2023 Chainguard</copyright><lastBuildDate>Thu, 13 Apr 2023 08:49:15 +0000</lastBuildDate><atom:link href="https://deploy-preview-3716--ornate-narwhal-088216.netlify.app/platform/administration/custom-idps/index.xml" rel="self" type="application/rss+xml"/><item><title>Using Custom Identity Providers to Authenticate to Chainguard</title><link>https://deploy-preview-3716--ornate-narwhal-088216.netlify.app/platform/administration/custom-idps/custom-idps/</link><pubDate>Mon, 17 Apr 2023 08:48:45 +0000</pubDate><guid>https://deploy-preview-3716--ornate-narwhal-088216.netlify.app/platform/administration/custom-idps/custom-idps/</guid><description>&lt;p&gt;The Chainguard platform supports Single Sign-on (SSO) authentication for users. By default, users can log in with GitHub, GitLab, and Google, but SSO support allows users to bring their own identity provider for authentication. This is helpful when your organization mandates using a corporate identity provider — like Okta or Azure Active Directory — to authenticate to SaaS products.&lt;/p&gt;
&lt;h2 id="usage" class="heading-2" data-heading-level="2"&gt;
&lt;span class="heading-text"&gt;Usage&lt;/span&gt;
&lt;a href="#usage" class="anchor" aria-label="Link to Usage" title="Link to this section"&gt;
&lt;svg width="16" height="9" viewBox="0 0 16 9" fill="none" xmlns="http://www.w3.org/2000/svg" aria-hidden="true"&gt;
&lt;path d="M6.833 8.125H4C3 8.125 2.146 7.77067 1.438 7.062C0.729333 6.354 0.375 5.5 0.375 4.5C0.375 3.5 0.729333 2.646 1.438 1.938C2.146 1.22933 3 0.875 4 0.875H6.833V1.958H4C3.30533 1.958 2.708 2.208 2.208 2.708C1.708 3.208 1.458 3.80533 1.458 4.5C1.458 5.19467 1.708 5.792 2.208 6.292C2.708 6.792 3.30533 7.042 4 7.042H6.833V8.125ZM5.208 5.042V3.958H10.792V5.042H5.208ZM9.167 8.125V7.042H12C12.6947 7.042 13.292 6.792 13.792 6.292C14.292 5.792 14.542 5.19467 14.542 4.5C14.542 3.80533 14.292 3.208 13.792 2.708C13.292 2.208 12.6947 1.958 12 1.958H9.167V0.875H12C13 0.875 13.854 1.22933 14.562 1.938C15.2707 2.646 15.625 3.5 15.625 4.5C15.625 5.5 15.2707 6.354 14.562 7.062C13.854 7.77067 13 8.125 12 8.125H9.167Z" fill="currentColor"/&gt;
&lt;/svg&gt;
&lt;/a&gt;
&lt;/h2&gt;&lt;p&gt;Once an administrator has &lt;a href="https://deploy-preview-3716--ornate-narwhal-088216.netlify.app/platform/administration/custom-idps/custom-idps/#setup-and-administration"&gt;configured an identity provider&lt;/a&gt; and set up their organization, users can authenticate at the command line and in the web console using the identity provider’s organization.&lt;/p&gt;</description></item><item><title>Grant Chainguard Roles from Identity Provider Groups</title><link>https://deploy-preview-3716--ornate-narwhal-088216.netlify.app/platform/administration/custom-idps/grant-roles-from-groups/</link><pubDate>Wed, 01 Jul 2026 08:48:45 +0000</pubDate><guid>https://deploy-preview-3716--ornate-narwhal-088216.netlify.app/platform/administration/custom-idps/grant-roles-from-groups/</guid><description>&lt;p&gt;Chainguard can grant roles based on a user&amp;rsquo;s groups in your identity provider (IdP). You map an IdP group to a Chainguard role once, and from then on any user who logs in with that group in their token receives the role for that session. Access follows group membership, so you manage who gets what in your IdP instead of assigning roles to each user in Chainguard.&lt;/p&gt;
&lt;p&gt;This guide covers Okta and Microsoft Entra ID. The Chainguard-side steps (2 through 4) are the same for both providers; only how you emit group membership in Step 1 differs.&lt;/p&gt;</description></item><item><title>Disabling Default Social Logins</title><link>https://deploy-preview-3716--ornate-narwhal-088216.netlify.app/platform/administration/custom-idps/disabling-social-logins/</link><pubDate>Thu, 02 Jul 2026 08:48:45 +0000</pubDate><guid>https://deploy-preview-3716--ornate-narwhal-088216.netlify.app/platform/administration/custom-idps/disabling-social-logins/</guid><description>&lt;p&gt;By default, users can authenticate to the Chainguard platform with a built-in social login provider: GitHub, GitLab, or Google. After you &lt;a href="https://deploy-preview-3716--ornate-narwhal-088216.netlify.app/chainguard/administration/custom-idps/custom-idps/#setup-and-administration"&gt;configure a custom identity provider&lt;/a&gt; for single sign-on (SSO), you may want to require that everyone in your organization authenticate through that provider instead.&lt;/p&gt;
&lt;p&gt;A common problem for SSO customers is that users click &lt;strong&gt;Login with Google&lt;/strong&gt; (or another social provider) out of habit. Because a personal or non-federated Google account isn&amp;rsquo;t tied to your organization, this creates an account &lt;em&gt;outside&lt;/em&gt; it that an owner then has to clean up and re-provision. Preventing social logins keeps account lifecycle, group membership, and security policies (such as multi-factor authentication) enforced centrally through your identity provider.&lt;/p&gt;</description></item><item><title>Enable PKCE for OAuth Token Exchange</title><link>https://deploy-preview-3716--ornate-narwhal-088216.netlify.app/platform/administration/custom-idps/enabling-pkce/</link><pubDate>Thu, 30 Jul 2026 08:48:45 +0000</pubDate><guid>https://deploy-preview-3716--ornate-narwhal-088216.netlify.app/platform/administration/custom-idps/enabling-pkce/</guid><description>&lt;p&gt;You can add PKCE (Proof Key for Code Exchange, commonly referred to as &amp;ldquo;pixy&amp;rdquo;) to the OAuth token exchange between Chainguard and your custom identity provider (IdP). PKCE is a security extension to OAuth that adds an extra layer of protection against authorization code interception during login, and it is required by the OAuth 2.1 standard.&lt;/p&gt;
&lt;p&gt;Chainguard supports two configurations, depending on your needs:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Client ID + client secret + PKCE&lt;/strong&gt; — In this configuration, PKCE is layered on top of your existing confidential client setup. This is additive: you keep your client ID and client secret.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Client ID + PKCE only, no client secret&lt;/strong&gt; — This is the newer &amp;ldquo;public client&amp;rdquo; model where PKCE replaces the client secret entirely, and is the approach OAuth 2.1 requires going forward.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Enabling PKCE is optional. If you leave PKCE disabled or optional on your IdP, your login behavior remains unchanged and you don&amp;rsquo;t need to take any action.&lt;/p&gt;</description></item><item><title>Identity Provider Examples</title><link>https://deploy-preview-3716--ornate-narwhal-088216.netlify.app/platform/administration/custom-idps/idp-providers/</link><pubDate>Thu, 16 Jan 2025 08:49:15 +0000</pubDate><guid>https://deploy-preview-3716--ornate-narwhal-088216.netlify.app/platform/administration/custom-idps/idp-providers/</guid><description/></item></channel></rss>