Bitfocus AS
logo
logo
Bitfocus AS
logo
logo
Sign upSign in

Loading...

Bitfocus

Subscribe to our newsletter

The latest news, articles, and resources, sent to your inbox.

FacebookInstagramGitHubYouTubeLinkedIn

Products

  • Buttons
  • Companion

Integrations

  • Supported Devices
  • Developer Community
  • Connection Development

Support

  • Support Overview
  • Documentation
  • Video Tutorials
  • Community Forum

Sales

  • Resellers & Integrators
  • Buttons Pricing

Updates

  • Case Studies
  • Events & Trade Shows
  • Press Releases
  • Product Updates
  • Webinars

Legal

  • Legal Overview
  • Privacy Policy
  • Buttons EULA
  • Terms & Cookie Policy

Company

  • About us
  • Press kit
  • Careers

© 2026 Bitfocus AS. All rights reserved.

SSO
Docs for
Buttons overview
Adding a License
Offline License
Debian/Ubuntu-headless build of Bitfocus Buttons
Position
Basic Section
Shift Section
Folder Section
Popover Section
Router Section v1.4.x
Router Section v1.6.x
Shared Section
Button
Presets
Internal Actions
Connect
Connection
NMOS
Surface
Workflow
Workflow Examples
Workflow node reference
Cuelist
Tags
Routing
Auth
SSO
Settings
Certificate
Network ports reference
Variables
Functions Reference
Functions
Operators

Loading...

Previous
← Auth
Next
Settings →
Contact support →
Buttons/User Management/SSO

SSO

Buttons supports Single Sign-On (SSO), allowing organizations to authenticate users through their existing identity provider. Users are automatically provisioned on first login, no manual account creation required. SSO can coexist with local authentication, or be set as the default login method. Connections can be enabled and disabled individually, and multiple providers can be active at the same time.

Supported Providers#

Provider
Protocol
User Provisioning
Group/Role Mapping
Google
OIDC (OAuth 2.0)
Automatic (JIT)
Planned
Microsoft Entra ID
OIDC (OAuth 2.0)
Automatic (JIT)
Planned
LDAP / Active Directory
LDAP Bind
Automatic (JIT)
Planned
Okta
OIDC (OAuth 2.0)
Automatic (JIT)
Planned
GitHub
OAuth 2.0
Automatic (JIT)
Planned

Feature Overview#

Feature
Status
Just-in-time user provisioning
Supported
Multiple simultaneous connections
Supported
Domain-restricted SSO
Supported
SSO as default login method
Supported
Local + SSO coexistence
Supported
Per-connection enable/disable
Supported
Role mapping from SSO groups
Planned
SCIM provisioning
Not supported. Can be evaluated based on demand.

Role & Group Mapping#

Automatic mapping from SSO groups to Buttons roles is not yet supported. An administrator can assign roles to SSO users after their first login. Since users are auto-provisioned, this only needs to happen once per user.

SSO Configuration #

You will find the SSO configuration under Settings, on the starting page you  can enable and disable SSO, Set the default login type, limit the allowed email domains and you can add SSO Providers.
Here we have chosen to add Google as a SSO provider. If you want to use multiple accounts from the same provider, make sure that you give them a propper display name so you can tell them apart.

You have to enter the OAuth Credentials and Client Secret from your Provider  and also enter the Workspace domain the the OAuth belongs to 

And if you have any additional scopes for the provider you can specify them as well.
The last thing you have to make sure of, is that your server is accessible from the internet, by specifying  the Buttons External address. This is for the SSO provider to be able to redirect the user to your buttons server after logging in. 

If this is missing  the main SSO page will warn you 

Was this helpful?

Was this helpful?

0 of 0 users found this page helpful