Overview
OIDC SSO protects the Dashboard and supports Authorization Code flow with PKCE, state and nonce validation, discovery, and signedHttpOnly,
SameSite=Lax sessions.
Unlike other Pro features, an explicitly enabled SSO configuration fails
closed: startup aborts when the sso entitlement is missing or the
configuration is invalid, so an authentication boundary cannot disappear
silently.
Configure SSO
Configure it underextensions.sso in the main GoModel YAML configuration:
PRO_SSO_* environment variables override the YAML values. The redirect URL
must end in /sso/callback (including any configured BASE_PATH), and HTTPS
is required except for loopback development URLs. By default, at least one
administrator group is required; set PRO_SSO_ALLOW_ALL_ADMINS=true only for
an intentionally unrestricted OIDC client.
Audit and access control
Successful logins, rejected policies, and logouts are recorded as sanitized audit events. Tokens, authorization codes, cookies, raw claims, and provider error details are not stored. An SSO session carries auser_path like a managed API key does, so the
group- and user-level model allowlists on the Users page
apply to requests made through it. Per-key allowed_models are a managed
API key setting and do not apply to SSO sessions.