Skip to content

Sign in with your organization's accounts

For the person who set up Stuga.

For the person who set up Stuga. You need access to Settings → This node and someone who can register Stuga with an OpenID Connect sign-in service (an identity provider).

  1. Open Settings → This node → Access, then Identity provider.
  2. Fill in Issuer URL and Client ID from your sign-in service.
  3. Fill in Client secret if your service requires one.
  4. Optionally, set Button label to the name people should see on the sign-in button.
  5. At your sign-in service, register the callback addresses listed on the Access page. Use Copy beside each address.
  6. Choose Save.

Saving checks that Stuga can use the service’s issuer address. Test a sign-in before inviting people: a wrong client ID or secret only shows up then. The computer running Stuga must be able to reach the service.

New people open their invite link and choose the button named for your sign-in service, then create their Stuga account.

If you already have an account, open Settings → Profile and choose Link in the section named for your service. You can also use the service’s sign-in button, choose I already have an account, enter your Stuga username and password, then choose Link and sign in. Stuga never links accounts by matching their email or username.

To unlink your account, set a password first, then choose Unlink in Settings → Profile.

Disabling someone at your sign-in service stops their next sign-in through it, but keeps their current Stuga sign-in working. To end their access, in Settings → This node → Access, select them under Account recovery and choose Revoke everything. Read the confirmation: this also removes their password, passkeys, service link, connected apps, keys and share links. Then remove them from each workspace’s Members and, if appointed, from Administrators under Access.

Removing the provider or changing Issuer URL unlinks accounts without signing people out. Anyone without a password should set one in Settings → Profile while signed in, or receive a reset link.

More detail for people who run servers: Identity provider on GitHub.