Bitfocus AS
logo
logo
Bitfocus AS
logo
logo
Sign upSign in

Loading...

Bitfocus

Subscribe to our newsletter

The latest news, articles, and resources, sent to your inbox.

FacebookInstagramGitHubYouTubeLinkedIn

Products

  • Buttons
  • Companion

Integrations

  • Supported Devices
  • Developer Community
  • Connection Development

Support

  • Support Overview
  • Documentation
  • Video Tutorials
  • Community Forum

Sales

  • Resellers & Integrators
  • Buttons Pricing

Updates

  • Case Studies
  • Events & Trade Shows
  • Press Releases
  • Product Updates
  • Webinars

Legal

  • Legal Overview
  • Privacy Policy
  • Buttons EULA
  • Terms & Cookie Policy

Company

  • About us
  • Press kit
  • Careers

© 2026 Bitfocus AS. All rights reserved.

Connect a generic OIDC provider
Docs for
Overview
Getting started
What is Bitfocus Buttons?
Install Buttons and get started
Manage your Buttons license
Activate Buttons offline
Find your way around Buttons
Create your first backup
Add an ATEM connection
Choose a control method
Choose an installation path
Install Buttons on Debian or Ubuntu
Understand HA clustering
Kubernetes HA
Update or remove Buttons
Positions
Understand positions
Create a position
Add controls and sections to a position
Create your first button
Use a connection's presets
Build more capable button actions
Add more feedback to a button
Organize controls in a section
Shift Section
Organize controls with a Folder Section
Add a Popover Section
Build and reuse a Shared Section
Build a Router Section
Understand Custom Routers
Custom Router panel
Surfaces
Surface compatibility
Add and attach a surface
Device orientation
Connections
Update a connection's module safely
Monitor and troubleshoot a connection
Router integrations
VideoHub and AJA KUMO
Utah Scientific BPS
Generic SW-P-08
Nevion VideoIPath
Arkona BLADE//runner
Routing
Physical routing
Configure ports and labels
Take a physical route
Understand route status
Topology graph
Routing Presets
Get started with virtual routing
Configure Nested Shapes
Reverse routing
Tielines
Routing Projects
Routing settings
Troubleshoot a route
Tally
Understand the Tally system
Send ATEM tally and labels to a UMD
Interpret Active Tally state
TSL/UMD connections
Diagnose tally problems
NMOS
Understand NMOS in Buttons
Connect Buttons to an NMOS Registry
Built-in Registry Server
Configure NMOS connections
Discover and adopt
Browse the NMOS inventory
Manage NMOS multicast addresses
Diagnose NMOS problems
Understand Cuelists
Build a Cuelist
Read and advance a running Cuelist
Control a Cuelist from a Position
Workflows
Understand workflows
Build your first workflow
Reuse a group of workflow nodes safely
Troubleshoot a workflow
Recipes
Sequence a timed automation
Call an HTTP endpoint from a workflow
REST endpoint
Use variables
Understand variable scope
Understand nested variables
Update expressions for v1.8
Plan and use Tags
Access
Create and manage users
Create roles and assign permissions
Grant access to specific resources
Show different controls by role
Sessions
Set up PIN and NFC sign-in
SSO
Get started with SSO
Connect a generic OIDC provider
Connect LDAP or Active Directory
Map identity claims to roles
Secure a Buttons deployment
Integrations
External control
Connect to Bitfocus Listener
USB Relay
Install USB Relay on Windows
Install USB Relay on macOS
Install USB Relay on Linux
Install USB Relay on a Raspberry Pi
Get started with the Control API
Secure and monitor the Control API
Control API reference
API reference
Administration
Enable and manage installable features
Services and health
Configure and monitor scheduled backups
Restore a backup and verify it
Export or import Buttons configuration
Store and rotate connection secrets
Replace the HTTPS certificate
HA backup and recovery
Settings
Collect support information
Reference
Glossary
Button Inspector reference
Network ports reference
Expressions
Internal actions reference
Routing Presets panel reference
Startup configuration reference
Workflow nodes
Connection workflow nodes
Workflow workflow nodes
Internal workflow nodes
Position workflow nodes
API workflow nodes
Utility workflow nodes

Loading...

Previous
← Get started with SSO
Next
Connect LDAP or Active Directory →
Contact support →
You are viewing documentation for Buttons 1.8.See the docs for Buttons 1.6
Buttons/Access/SSO/Connect a generic OIDC provider

Connect a generic OIDC provider

Generic OIDC lets you sign in to Buttons through any OpenID Connect provider that supports Discovery, the Authorization Code flow, PKCE, and nonce, not just the named providers Buttons lists separately (Google, Microsoft Entra ID, GitHub, Okta).

Before you begin#

  • An Enterprise license: SSO is gated to this tier.
  • Buttons' public address configured (Environment Settings → Editor Listen Address, or equivalent): the callback URL is built from this, and OIDC won't work without it.
  • Your identity provider's Issuer URL, and the ability to register a Client ID/Secret and a redirect URI with it.
  • ID tokens signed with RS256 or ES256: Buttons doesn't support other signing algorithms.

Register Buttons with your provider#

  1. Open Settings → SSO and create a new connection with Provider set to Generic OIDC.
  2. Before filling in the form, select Setup guide for a copyable callback URL and a short checklist.
  3. In your identity provider, register a confidential web application and set its redirect/callback URI to the copied value.
  4. Note the application's Client ID and Client Secret, and the provider's Issuer URL exactly as its own discovery document advertises it.
If Buttons' public address isn't configured yet, the setup guide shows a warning instead of a callback URL, and the connections list shows the same warning until it's set.

Configure the connection#

  1. Enter a Display name for this connection.
  2. Enter the Client ID and Client secret from your provider.
  3. Enter the Issuer URL. It must use HTTPS unless the host is specifically allowlisted for HTTP (intended for local testing, not production).
  4. Add any Additional scopes beyond the defaults Buttons always requests (openid, profile, email).
  5. Save.

Note

The Client Secret is stored directly on this connection's own record, not through the same Secrets vault used for connection credentials elsewhere in Buttons. Treat access to the SSO connection list itself as sensitive.

Map claims to roles#

Once the connection exists, a Role mappings section appears. Add a mapping with a Claim name (for example, groups), a Claim value matching what your provider actually sends, and the Local role it should grant. You can add several mappings pointing at the same role, or several roles from different claim values: there's no one-to-one restriction.
Use Test mappings to paste a sample of decoded ID-token claims and see which roles it would grant, without contacting your provider: useful for confirming a mapping is shaped correctly before a real user tries to sign in. See Map identity claims to roles for how this actually behaves at sign-in time, including what happens when a user's claims change on a later login.

Test the connection#

There's no separate "Test connection" button for OIDC: checking discovery and issuer configuration happens automatically the moment anyone selects this sign-in option, before they're redirected to your provider. If the issuer is unreachable, doesn't match, or doesn't advertise a supported signing algorithm, the error appears inline on the login page immediately, rather than after a full round trip through your provider.
Confirm the connection actually works by signing in with it yourself once, using an account your mapped roles cover.

Recover from a misconfiguration#

Local username/password sign-in stays available on the same login page no matter what state this connection is in: a broken OIDC connection doesn't remove it. If something's wrong, the login page shows a plain-language message rather than a raw error:
What a user sees
What it means
"Single Sign-On is not ready because the external Buttons address is not configured."
Buttons' public address isn't set: configure it before OIDC can work at all.
"This sign-in connection is not properly configured."
The Client ID or Client Secret is missing.
An error before being redirected to your provider (issuer mismatch, discovery failure, unsupported signing algorithm)
The Issuer URL or provider configuration is wrong: Buttons catches this before sending the user anywhere.
"Sign-in failed. Please try again." (after returning from your provider)
The Client Secret is likely wrong, or the token exchange failed.
"Your sign-in session has expired. Please try again."
The user took too long, or reused an old sign-in link.

If you get stuck#

What you see
What to try
The setup guide shows no callback URL.
Configure Buttons' public address first: the callback URL can't be generated without it.
Sign-in fails immediately, before reaching your provider.
Check the Issuer URL matches your provider's discovery document exactly, and that it's HTTPS (or explicitly allowlisted).
Sign-in fails right after returning from your provider.
Double-check the Client Secret: this is the most common cause of a post-redirect failure.
A user signs in but doesn't get the role you expected.
Use Test mappings with a real sample of their claims to check your mapping actually matches what the provider sends.
You're worried about being locked out while testing.
You won't be: local sign-in remains available on the same login page throughout, regardless of this connection's state.

Where to go next#

  • Get started with SSO
  • Map identity claims to roles
  • Connect LDAP or Active Directory

Was this helpful?

Was this helpful?

0 of 0 users found this page helpful