[{"data":1,"prerenderedAt":777},["ShallowReactive",2],{"navigation_docs_en":3,"-en-guides-configure-sso":270,"-en-guides-configure-sso-surround":772},[4,30,68,98,182,260],{"title":5,"icon":6,"path":7,"stem":8,"children":9,"page":6},"Getting Started",false,"\u002Fen\u002Fgetting-started","en\u002F1.getting-started",[10,15,20,25],{"title":11,"path":12,"stem":13,"icon":14},"Introduction","\u002Fen\u002Fgetting-started\u002Fintroduction","en\u002F1.getting-started\u002F2.introduction","i-lucide-house",{"title":16,"path":17,"stem":18,"icon":19},"Quickstart","\u002Fen\u002Fgetting-started\u002Finstallation","en\u002F1.getting-started\u002F3.installation","i-lucide-download",{"title":21,"path":22,"stem":23,"icon":24},"Use Cases","\u002Fen\u002Fgetting-started\u002Fuse-cases","en\u002F1.getting-started\u002F4.use-cases","i-lucide-layers",{"title":26,"path":27,"stem":28,"icon":29},"Concepts","\u002Fen\u002Fgetting-started\u002Fconcepts","en\u002F1.getting-started\u002F5.concepts","i-lucide-book",{"title":26,"path":31,"stem":32,"children":33,"page":6},"\u002Fen\u002Fconcepts","en\u002F2.concepts",[34,38,43,48,53,58,63],{"title":35,"path":36,"stem":37,"icon":14},"Organization","\u002Fen\u002Fconcepts\u002Forganization","en\u002F2.concepts\u002F1.organization",{"title":39,"path":40,"stem":41,"icon":42},"Data Model","\u002Fen\u002Fconcepts\u002Fdata-model","en\u002F2.concepts\u002F2.data-model","i-lucide-database",{"title":44,"path":45,"stem":46,"icon":47},"Access Control","\u002Fen\u002Fconcepts\u002Faccess-permissions","en\u002F2.concepts\u002F3.access-permissions","i-lucide-user-key",{"title":49,"path":50,"stem":51,"icon":52},"Audit Logs","\u002Fen\u002Fconcepts\u002Faudit-logs","en\u002F2.concepts\u002F4.audit-logs","i-lucide-scroll-text",{"title":54,"path":55,"stem":56,"icon":57},"Introspection","\u002Fen\u002Fconcepts\u002Fintrospection","en\u002F2.concepts\u002F6.introspection","i-lucide-database-search",{"title":59,"path":60,"stem":61,"icon":62},"Query Engine","\u002Fen\u002Fconcepts\u002Fquery-engine","en\u002F2.concepts\u002F7.query-engine","i-lucide-workflow",{"title":64,"path":65,"stem":66,"icon":67},"AI","\u002Fen\u002Fconcepts\u002Fai","en\u002F2.concepts\u002F8.ai","i-lucide-sparkles",{"title":69,"path":70,"stem":71,"children":72,"page":6},"Guides","\u002Fen\u002Fguides","en\u002F4.guides",[73,78,83,88,93],{"title":74,"path":75,"stem":76,"icon":77},"REST API Quickstart","\u002Fen\u002Fguides\u002Frest-api","en\u002F4.guides\u002F1.rest-api","i-lucide-plug",{"title":79,"path":80,"stem":81,"icon":82},"SDK Quickstart","\u002Fen\u002Fguides\u002Fsdk","en\u002F4.guides\u002F2.sdk","i-lucide-terminal",{"title":84,"path":85,"stem":86,"icon":87},"Configure SSO","\u002Fen\u002Fguides\u002Fconfigure-sso","en\u002F4.guides\u002F3.configure-sso","i-lucide-key-round",{"title":89,"path":90,"stem":91,"icon":92},"Configure MCP","\u002Fen\u002Fguides\u002Fmcp","en\u002F4.guides\u002F4.mcp","i-lucide-brain-cog",{"title":94,"path":95,"stem":96,"icon":97},"Customize Content Space","\u002Fen\u002Fguides\u002Fcustomize-content-space","en\u002F4.guides\u002F5.customize-content-space","i-lucide-columns-3-cog",{"title":99,"path":100,"stem":101,"children":102,"page":6},"Developer","\u002Fen\u002Fdeveloper","en\u002F5.developer",[103,158],{"title":104,"path":105,"stem":106,"children":107,"page":6},"Data Access","\u002Fen\u002Fdeveloper\u002Fapi","en\u002F5.developer\u002F1.api",[108,113,118,123,128,133,138,143,148,153],{"title":109,"path":110,"stem":111,"icon":112},"Overview","\u002Fen\u002Fdeveloper\u002Fapi\u002Foverview","en\u002F5.developer\u002F1.api\u002F1.overview","i-lucide-globe",{"title":114,"path":115,"stem":116,"icon":117},"Errors","\u002Fen\u002Fdeveloper\u002Fapi\u002Ferrors","en\u002F5.developer\u002F1.api\u002F10.errors","i-lucide-alert-triangle",{"title":119,"path":120,"stem":121,"icon":122},"Authentication","\u002Fen\u002Fdeveloper\u002Fapi\u002Fauthentication","en\u002F5.developer\u002F1.api\u002F2.authentication","i-lucide-lock",{"title":124,"path":125,"stem":126,"icon":127},"Reading Data","\u002Fen\u002Fdeveloper\u002Fapi\u002Freading-data","en\u002F5.developer\u002F1.api\u002F3.reading-data","i-lucide-book-open",{"title":129,"path":130,"stem":131,"icon":132},"Writing Data","\u002Fen\u002Fdeveloper\u002Fapi\u002Fwriting-data","en\u002F5.developer\u002F1.api\u002F4.writing-data","i-lucide-pencil",{"title":134,"path":135,"stem":136,"icon":137},"Filtering","\u002Fen\u002Fdeveloper\u002Fapi\u002Ffiltering","en\u002F5.developer\u002F1.api\u002F5.filtering","i-lucide-filter",{"title":139,"path":140,"stem":141,"icon":142},"Field Selection","\u002Fen\u002Fdeveloper\u002Fapi\u002Ffield-selection","en\u002F5.developer\u002F1.api\u002F6.field-selection","i-lucide-list-checks",{"title":144,"path":145,"stem":146,"icon":147},"Sorting & Pagination","\u002Fen\u002Fdeveloper\u002Fapi\u002Fsorting-pagination","en\u002F5.developer\u002F1.api\u002F7.sorting-pagination","i-lucide-arrow-up-down",{"title":149,"path":150,"stem":151,"icon":152},"Relational Data","\u002Fen\u002Fdeveloper\u002Fapi\u002Frelational-data","en\u002F5.developer\u002F1.api\u002F8.relational-data","i-lucide-network",{"title":154,"path":155,"stem":156,"icon":157},"Files & Assets","\u002Fen\u002Fdeveloper\u002Fapi\u002Ffiles","en\u002F5.developer\u002F1.api\u002F9.files","i-lucide-file-up",{"title":159,"path":160,"stem":161,"children":162,"page":6},"Client SDK","\u002Fen\u002Fdeveloper\u002Fsdk","en\u002F5.developer\u002F2.sdk",[163,167,172,177],{"title":164,"path":165,"stem":166,"icon":19},"Installation","\u002Fen\u002Fdeveloper\u002Fsdk\u002Finstallation","en\u002F5.developer\u002F2.sdk\u002F1.installation",{"title":168,"path":169,"stem":170,"icon":171},"Client Setup","\u002Fen\u002Fdeveloper\u002Fsdk\u002Fclient-setup","en\u002F5.developer\u002F2.sdk\u002F2.client-setup","i-lucide-settings",{"title":173,"path":174,"stem":175,"icon":176},"Type System","\u002Fen\u002Fdeveloper\u002Fsdk\u002Ftype-system","en\u002F5.developer\u002F2.sdk\u002F3.type-system","i-lucide-braces",{"title":178,"path":179,"stem":180,"icon":181},"Advanced","\u002Fen\u002Fdeveloper\u002Fsdk\u002Fadvanced","en\u002F5.developer\u002F2.sdk\u002F5.advanced","i-lucide-puzzle",{"title":183,"path":184,"stem":185,"children":186,"page":6},"Reference","\u002Fen\u002Freference","en\u002F6.reference",[187,191,207,211,216,231],{"title":188,"path":189,"stem":190,"icon":171},"Configuration","\u002Fen\u002Freference\u002Fenvironment-variables","en\u002F6.reference\u002F1.environment-variables",{"title":192,"path":193,"stem":194,"children":195,"icon":77},"Connectors","\u002Fen\u002Freference\u002Fconnectors","en\u002F6.reference\u002F2.connectors\u002Findex",[196,197,202],{"title":192,"path":193,"stem":194,"icon":77},{"title":198,"path":199,"stem":200,"icon":201},"PostgreSQL and Supabase","\u002Fen\u002Freference\u002Fconnectors\u002Fpostgresql-supabase","en\u002F6.reference\u002F2.connectors\u002F1.postgresql-supabase","i-simple-icons-postgresql",{"title":203,"path":204,"stem":205,"icon":206},"MySQL and MariaDB","\u002Fen\u002Freference\u002Fconnectors\u002Fmysql-mariadb","en\u002F6.reference\u002F2.connectors\u002F2.mysql-mariadb","i-simple-icons-mysql",{"title":208,"path":209,"stem":210,"icon":176},"Data Types Representation","\u002Fen\u002Freference\u002Fdata-types","en\u002F6.reference\u002F3.data-types",{"title":212,"path":213,"stem":214,"icon":215},"Permissions Reference","\u002Fen\u002Freference\u002Fpermissions","en\u002F6.reference\u002F4.permissions","i-lucide-shield",{"title":217,"path":218,"stem":219,"children":220,"page":6},"API Reference","\u002Fen\u002Freference\u002Fapi-reference","en\u002F6.reference\u002F5.api-reference",[221,226],{"title":222,"path":223,"stem":224,"icon":225},"System Endpoints","\u002Fen\u002Freference\u002Fapi-reference\u002Fsystem-endpoints","en\u002F6.reference\u002F5.api-reference\u002F1.system-endpoints","i-lucide-server",{"title":227,"path":228,"stem":229,"icon":230},"OpenAPI Spec","\u002Fen\u002Freference\u002Fapi-reference\u002Fopenapi-spec","en\u002F6.reference\u002F5.api-reference\u002F2.openapi-spec","i-lucide-file-code",{"title":232,"path":233,"stem":234,"children":235,"page":6},"Pitfalls","\u002Fen\u002Freference\u002Fpitfalls","en\u002F6.reference\u002F6.pitfalls",[236,240,245,250,255],{"title":109,"path":237,"stem":238,"icon":239},"\u002Fen\u002Freference\u002Fpitfalls\u002Foverview","en\u002F6.reference\u002F6.pitfalls\u002F1.overview","i-lucide-triangle-alert",{"title":241,"path":242,"stem":243,"icon":244},"Concurrent Migrations","\u002Fen\u002Freference\u002Fpitfalls\u002Fconcurrent-migrations","en\u002F6.reference\u002F6.pitfalls\u002F2.concurrent-migrations","i-lucide-git-merge",{"title":246,"path":247,"stem":248,"icon":249},"Instance Configuration","\u002Fen\u002Freference\u002Fpitfalls\u002Finstance-configuration-related-problems","en\u002F6.reference\u002F6.pitfalls\u002F3.instance-configuration-related-problems","i-lucide-wrench",{"title":251,"path":252,"stem":253,"icon":254},"Overly Permissive Public Roles","\u002Fen\u002Freference\u002Fpitfalls\u002Foverly-permissive","en\u002F6.reference\u002F6.pitfalls\u002F4.overly-permissive","i-lucide-shield-off",{"title":256,"path":257,"stem":258,"icon":259},"No Aggregates","\u002Fen\u002Freference\u002Fpitfalls\u002Fno-aggregates","en\u002F6.reference\u002F6.pitfalls\u002F5.no-aggregates","i-lucide-sigma",{"title":261,"icon":262,"path":263,"stem":264,"children":265,"page":6},"Release Notes","i-lucide-rocket","\u002Fen\u002Frelease-notes","en\u002F7.release-notes",[266],{"title":267,"path":268,"stem":269,"icon":262},"Changelog","\u002Fen\u002Frelease-notes\u002Fchangelog","en\u002F7.release-notes\u002F1.changelog",{"id":271,"title":84,"body":272,"description":765,"extension":766,"links":767,"meta":768,"navigation":769,"path":85,"seo":770,"stem":86,"__hash__":771},"docs_en\u002Fen\u002F4.guides\u002F3.configure-sso.md",{"type":273,"value":274,"toc":748},"minimark",[275,279,288,291,319,323,326,346,350,522,525,528,684,698,702,709,713,720,723,727],[276,277,109],"h2",{"id":278},"overview",[280,281,282,283,287],"p",{},"Monospace supports single sign-on (SSO) through any OAuth 2.0 identity provider, including Google, GitHub, Microsoft Entra, Okta, Auth0, and GitLab. Members sign in with their existing provider account instead of a Monospace password. You configure providers per organization under ",[284,285,286],"strong",{},"Settings → Sign-in Providers",", using a preset for a common provider or a custom configuration for any other.",[280,289,290],{},"Three behaviors shape how SSO works:",[292,293,294,307,313],"ul",{},[295,296,297,300,301,306],"li",{},[284,298,299],{},"Invitation-only."," SSO does not create accounts on its own. A member must be invited first, then completes signup with their provider — see ",[302,303,305],"a",{"href":304},"#invite-members","Invite members",".",[295,308,309,312],{},[284,310,311],{},"PKCE is always applied"," (S256). There is nothing to configure.",[295,314,315,318],{},[284,316,317],{},"The client secret is write-only."," Monospace never displays it again after you save it.",[276,320,322],{"id":321},"before-you-begin","Before You Begin",[280,324,325],{},"You need:",[292,327,328,331],{},[295,329,330],{},"Organization administrator access.",[295,332,333,334,337,338,341,342,345],{},"An OAuth 2.0 application registered with your identity provider. You exchange a ",[284,335,336],{},"callback URL"," from Monospace for a ",[284,339,340],{},"client ID"," and ",[284,343,344],{},"client secret"," from the provider.",[276,347,349],{"id":348},"add-a-sign-in-provider","Add a Sign-in Provider",[351,352,353,358,371,375,403,410,414,425,436,447,453,457,507,511],"steps",{},[354,355,357],"h3",{"id":356},"open-sign-in-providers","Open Sign-in Providers",[280,359,360,361,363,364,367,368,306],{},"In the Studio, go to ",[284,362,286],{}," (under ",[284,365,366],{},"Access","). The page lists every sign-in method for your organization. Select ",[284,369,370],{},"Add sign-in method",[354,372,374],{"id":373},"choose-a-provider","Choose a provider",[280,376,377,378,381,382,381,385,381,388,381,391,394,395,398,399,402],{},"Pick a preset — ",[284,379,380],{},"Google",", ",[284,383,384],{},"GitHub",[284,386,387],{},"GitLab",[284,389,390],{},"Microsoft Entra",[284,392,393],{},"Okta",", or ",[284,396,397],{},"Auth0"," — or choose ",[284,400,401],{},"Custom OAuth 2"," for any other provider. A preset fills in the endpoints, scopes, and claim mappings for you, so you only supply your client ID and secret.",[280,404,405],{},[406,407],"img",{"alt":408,"src":409},"The Add sign-in method dialog with provider presets","\u002Fimages\u002Fchangelog\u002F0-1-0\u002Fmonospace-sso.png",[354,411,413],{"id":412},"register-the-callback-url-with-your-provider","Register the callback URL with your provider",[280,415,416,417,420,421,424],{},"Choosing a provider opens its configuration form. The ",[284,418,419],{},"How to set this up"," panel shows the ",[284,422,423],{},"Callback URL"," alongside provider-specific setup steps. Copy the callback URL and add it as the authorized redirect URI in your provider's OAuth application. It has the form:",[426,427,432],"pre",{"className":428,"code":430,"language":431},[429],"language-text","https:\u002F\u002F{your-instance}\u002Fapi\u002Fauth\u002Fproviders\u002F{apiName}\u002Foauth2\u002Fcallback\n","text",[433,434,430],"code",{"__ignoreMap":435},"",[280,437,438,439,442,443,446],{},"The ",[433,440,441],{},"{apiName}"," segment comes from the provider's ",[284,444,445],{},"API Name"," — a preset supplies a default you can change; for a custom provider, set your own (letters, digits, underscores, and hyphens only).",[280,448,449],{},[406,450],{"alt":451,"src":452},"Configuring a Google sign-in provider","\u002Fimages\u002Fchangelog\u002F0-1-0\u002Fmonospace-sso-config.png",[354,454,456],{"id":455},"enter-your-credentials","Enter your credentials",[280,458,459,460,341,463,466,467,469,470,381,473,476,477,480,481,484,485,381,488,476,491,494,495,498,499,502,503,306],{},"Paste the ",[284,461,462],{},"Client ID",[284,464,465],{},"Client Secret"," from your provider's OAuth app. With a preset, the endpoints, scopes, and claim mappings are already filled in. For ",[284,468,401],{},", also enter the ",[284,471,472],{},"Authorization",[284,474,475],{},"Token",", and ",[284,478,479],{},"Userinfo"," endpoints, the ",[284,482,483],{},"Scopes"," to request (for example, ",[433,486,487],{},"openid",[433,489,490],{},"email",[433,492,493],{},"profile","), and the ",[284,496,497],{},"Subject"," claim — and optionally the ",[284,500,501],{},"Email"," claim. See ",[302,504,506],{"href":505},"#provider-configuration","Provider Configuration",[354,508,510],{"id":509},"save","Save",[280,512,513,514,517,518,521],{},"Select ",[284,515,516],{},"Create",". The provider appears in the list as ",[284,519,520],{},"Active"," and shows on the login screen immediately.",[276,523,506],{"id":524},"provider-configuration",[280,526,527],{},"These are the fields on the OAuth 2.0 provider form.",[529,530,531,547],"table",{},[532,533,534],"thead",{},[535,536,537,541,544],"tr",{},[538,539,540],"th",{},"Field",[538,542,543],{},"Required",[538,545,546],{},"Description",[548,549,550,563,576,587,598,610,622,634,645,660,672],"tbody",{},[535,551,552,557,560],{},[553,554,555],"td",{},[284,556,445],{},[553,558,559],{},"Yes",[553,561,562],{},"Short identifier used in the callback URL and login route. Letters, digits, underscores, and hyphens only.",[535,564,565,570,573],{},[553,566,567],{},[284,568,569],{},"Display Name",[553,571,572],{},"No",[553,574,575],{},"Overrides the label and icon shown on the login screen.",[535,577,578,582,584],{},[553,579,580],{},[284,581,462],{},[553,583,559],{},[553,585,586],{},"The public identifier from your provider's OAuth app.",[535,588,589,593,595],{},[553,590,591],{},[284,592,465],{},[553,594,559],{},[553,596,597],{},"The private secret from your provider's OAuth app. Write-only — leave blank when editing to keep the current value.",[535,599,600,605,607],{},[553,601,602],{},[284,603,604],{},"Authorization Endpoint",[553,606,559],{},[553,608,609],{},"Where members are sent to approve the sign-in.",[535,611,612,617,619],{},[553,613,614],{},[284,615,616],{},"Token Endpoint",[553,618,559],{},[553,620,621],{},"Where Monospace exchanges the authorization code for tokens.",[535,623,624,629,631],{},[553,625,626],{},[284,627,628],{},"Userinfo Endpoint",[553,630,559],{},[553,632,633],{},"Where Monospace reads the member's profile with the access token.",[535,635,636,640,642],{},[553,637,638],{},[284,639,483],{},[553,641,559],{},[553,643,644],{},"The scopes to request. Add at least one.",[535,646,647,652,654],{},[553,648,649],{},[284,650,651],{},"Subject Claim",[553,653,559],{},[553,655,656,657,306],{},"The profile field that uniquely identifies the external account. Supports dotted paths for nested claims, such as ",[433,658,659],{},"user.id",[535,661,662,667,669],{},[553,663,664],{},[284,665,666],{},"Email Claim",[553,668,572],{},[553,670,671],{},"The profile field containing the member's email. Supports dotted paths.",[535,673,674,679,681],{},[553,675,676],{},[284,677,678],{},"Extra Authorize Parameters",[553,680,572],{},[553,682,683],{},"Key\u002Fvalue pairs appended to the authorization URL. Reserved OAuth parameters are rejected.",[280,685,438,686,341,688,690,691,694,695,306],{},[284,687,497],{},[284,689,501],{}," claims map fields from the provider's userinfo response to the Monospace member. Use a dotted path when the value is nested — for a response of ",[433,692,693],{},"{ \"user\": { \"contact\": { \"email\": \"...\" } } }",", set the email claim to ",[433,696,697],{},"user.contact.email",[276,699,701],{"id":700},"sign-in","Sign In",[280,703,704,705,708],{},"Each enabled provider appears on the login screen as a ",[284,706,707],{},"Continue with {name}"," button, using the provider's name and icon. Monospace highlights the member's last-used method.",[276,710,712],{"id":711},"invite-members","Invite Members",[280,714,715,716,719],{},"SSO is invitation-only — there is no just-in-time signup. Invite a member to the organization or a workspace as usual; the roles you assign in the invitation are the roles they receive, not the identity provider. When the member opens the invitation, they enter their full name and select ",[284,717,718],{},"Sign Up with {provider}"," to complete signup.",[280,721,722],{},"Members who already have an account can link an SSO identity to it, then sign in with either method.",[276,724,726],{"id":725},"see-also","See Also",[292,728,729,735,742],{},[295,730,731,734],{},[302,732,222],{"href":733},"\u002Freference\u002Fapi-reference\u002Fsystem-endpoints"," — The auth-provider API, for scripting provider setup across environments",[295,736,737,741],{},[302,738,740],{"href":739},"\u002Fconcepts\u002Faccess-permissions","Access & Permissions"," — Roles and entitlements, including who can manage sign-in providers",[295,743,744,747],{},[302,745,49],{"href":746},"\u002Fconcepts\u002Faudit-logs"," — Account creation and membership changes are recorded in the audit log",{"title":435,"searchDepth":749,"depth":749,"links":750},2,[751,752,753,761,762,763,764],{"id":278,"depth":749,"text":109},{"id":321,"depth":749,"text":322},{"id":348,"depth":749,"text":349,"children":754},[755,757,758,759,760],{"id":356,"depth":756,"text":357},3,{"id":373,"depth":756,"text":374},{"id":412,"depth":756,"text":413},{"id":455,"depth":756,"text":456},{"id":509,"depth":756,"text":510},{"id":524,"depth":749,"text":506},{"id":700,"depth":749,"text":701},{"id":711,"depth":749,"text":712},{"id":725,"depth":749,"text":726},"Let members sign in to Monospace with an external identity provider over OAuth 2.0.","md",null,{},{"icon":87},{"title":84,"description":765},"Z9NnJhCXVC0SIOsWoOBV3jKCy7WQ9ewubCs_W43I7w4",[773,775],{"title":79,"path":80,"stem":81,"description":774,"icon":82,"children":-1},"Install the Monospace SDK, generate types from your schema, and query your data with full TypeScript autocomplete.",{"title":89,"path":90,"stem":91,"description":776,"icon":92,"children":-1},"Connect AI agents to your Monospace workspace through the Model Context Protocol.",1784053973599]