Skip to content

Configure sign-in

Helmhive authenticates through a platform account by default. A workspace can add its own OpenID Connect provider (Company SSO), test it, activate it, and then decide whether platform accounts, Company SSO, or both are allowed.

  1. Choose Add provider under Add Company SSO, then enter a Provider name, the Issuer URL, the Client ID, and the Client secret. Choose Save SSO draft.
  2. When the provider shows Run test login as its next step, choose Test login and complete a real sign-in with your own identity. A test that comes back as a different identity, an unverified email, or a failed exchange is reported on the page with a specific reason.
  3. When the provider shows Tested, choose Activate Company SSO. The sign-in policy is not changed by activation.

Each provider card shows its setup stages (Draft, Tested, Active, Disabled), the broker state, and the next step. Changes are applied asynchronously and stay visible until the broker converges.

Under Sign-in policy, pick the Allowed sign-in methods:

  • Wavyzz account only
  • Wavyzz account and Company SSO
  • Company SSO required

Company SSO required is available only while at least one provider is active. When it applies, every member must sign in through Company SSO; only the recovery owner named on the page keeps platform-account sign-in, so the workspace cannot lock itself out. Disabling the last active provider under that policy leaves only the recovery owner able to sign in, and the confirmation says so.