Identity Providers

An identity provider (IdP) is the OIDC system your tenant uses for SSO: Google, Okta, Microsoft, or a private OIDC issuer. Poly stores the issuer URL, client id, and client secret, then uses them on /canopy/<subpath>/auth/finish-oauth.

SSO is OIDC only today. SAML is not supported for customers.

Register the IdP in Canopy (see Setting up Single Sign-On steps 4–5):

  1. Create a client app in the IdP. Copy client id and client secret.

  2. In Poly, set the issuer URL (for Google: https://accounts.google.com; for Okta: your Okta domain).

  3. Paste client id and secret, and enable the provider.

  4. After you create the PUBLIC Application, finish the IdP redirect URLs using your instance and Application subpath.

The login Application is a separate resource. It must have visibility=PUBLIC or teammates cannot use the login URL. That is not an IdP-console “public client” setting.

Related: Authentication model, Setting up Single Sign-On.