basalt / auth/src / oidcProvider
Function: oidcProvider()
> oidcProvider(config): OAuthProvider
Defined in: auth/src/oauth.ts:206
A generic OIDC provider — enterprise SSO for any OpenID Connect IdP (Okta, Azure AD / Entra ID, Auth0, Google Workspace, Keycloak…). Pass the three endpoints from the IdP's .well-known/openid-configuration, or use discoverOidcProvider to fetch them for you. Maps the standard OIDC userinfo claims (sub, email, email_verified, name).
The IdP's admin decides which emails it asserts as verified: restrict each customer's IdP to that customer's domains with allowedEmailDomains — required as soon as more than one provider is configured (see OAuthProvider.enterprise).
Parameters
config
OidcConfig