Back to release notes
Enterprise SSO Improvements

Hardened SAML/OIDC SSO Security and Recovery

SAML manual configuration, OIDC PKCE code exchange, SSO failure recovery, and domain validation messaging have been improved for Enterprise SSO.

Enterprise SSO has been hardened with several security and reliability improvements.

This release includes:

  • Manually configured SAML now works correctly by falling back to the stored IdP certificate when no metadata URL is set
  • OIDC sign-in now uses a secure PKCE code exchange flow
  • Organization owners and admins can fall back to email/password sign-in if their configured SSO fails
  • Domain validation errors show a clear, user-friendly message instead of a raw HTTP error

These changes make SSO setup more forgiving and give admins a way to recover access if an SSO configuration issue locks them out.