Skip to main content
← Back to list
01Issue
FeatureShippedSwamp Club
Assigneesstack72

Relationships

#1170 SSO admin setup guide for swamp-club

Opened by stack72 · 7/15/2026· Shipped 7/16/2026

Summary

Document the end-to-end SSO admin setup flow in swamp-club. This is the guide we send to ourselves (and eventually customers) covering how to configure an IdP connection and onboard enterprise users.

Content to cover

  1. Creating an SSO connection — using the admin UI at /admin/sso, what fields to fill in (display name, email domain, collective), what gets auto-created (the collective if it doesn't exist)
  2. Sharing setup details with the customer — the ACS URL and SP Entity ID generated after provider creation, what to tell the customer to configure in Okta/Entra/Keycloak
  3. Completing the connection — adding the customer's IdP metadata URL once they provide it
  4. Attribute mapping — what claims we expect (email, displayName, groups), how group filtering works on the IdP side
  5. Testing the connection — how to verify SSO login works, how to check that groups are captured on the user record and returned on userinfo
  6. Ongoing operations — what happens when users are added/removed from IdP groups, how the swamp serve refresh loop keeps things current, deprovisioning behaviour

Notes

  • This is the swamp-club side companion to swamp issue #1166 (IdP group docs in the serve guide)
  • The SSO plugin, admin UI, group extraction, and collective auto-assignment are all shipped
  • Reference the customer-facing SSO setup artifact already created for the format/tone of customer-facing sections
02Bog Flow
OPENTRIAGEDIN PROGRESSSHIPPED+ 1 MOREASSIGNED+ 5 MOREREVIEW+ 3 MOREPR_MERGED+ 1 MORENOTIFICATION_SKIPPED

Shipped

7/16/2026, 12:20:05 AM

Click a lifecycle step above to view its details.

03Sludge Pulse
stack72 assigned stack727/15/2026, 11:48:49 PM

Sign in to post a ripple.