SSO & cloud providers

SSO & cloud providers

Sign-in, API keys, roles, SSO, and linking cloud accounts.

How people and machines prove who they are, and what they're allowed to do once they're in.

In this section

  • How sign-in works - magic-link and device-code; no passwords.
  • API keys - headless, scoped tokens for scripts and CI.
  • Roles & scopes - viewer · editor · builder · admin, and how key scopes narrow them.
  • SSO with OIDC - Okta, Entra ID, Auth0, Keycloak, and other OIDC providers.
  • Link cloud accounts - register a per-org Azure/Google OAuth app, then link accounts to enumerate storage and discover tables.

Two different "OAuth" things

Don't confuse them:

  • SSO sign-in (OIDC) - how a human logs in to Eddytor via your IdP.
  • Linking a cloud account - how a user grants Eddytor delegated access to their cloud storage (Azure/Google) for discovery.

They're configured separately.

On this page