Skip to content

Works with account required

Generic OpenID Connect

Generic OIDC is the core SSO protocol. The connector discovers the issuer, authenticates with PKCE, maps groups/roles, supports logout and records the IdP subject. Tokens are encrypted.

Verification: test_verified. Connection: unknown. Credentials: none. Live E2E: no.

No disposable OIDC issuer is configured for this environment.

What sslcertificates.io can do

Generic OIDC is the core SSO protocol. The connector discovers the issuer, authenticates with PKCE, maps groups/roles, supports logout and records the IdP subject. Tokens are encrypted. Capabilities: login, group_mapping, sso_enforcement, logout, break_glass. Authentication uses oidc.

Required permissions

Authorization Code with PKCE. Discovery from /.well-known/openid-configuration.

Setup

Open Dashboard → Integrations → Generic OpenID Connect. Enter the credentials described on this page. Values are encrypted at rest and never shown again. Run Test connection. Discovery runs only after authentication succeeds. Select a discovered resource. Do not paste opaque IDs unless the provider cannot enumerate them. Perform the certificate or notification action, then confirm the external system matches. Disconnect removes stored credentials and owned test resources created by sslcertificates.io.

Known limitations

Break-glass platform owner passwords remain available. SSO enforcement is per organization.

Official sources

Fact checked 2026-09-20. https://openid.net/specs/openid-connect-core-1_0.html Generic OpenID Connect is a trademark of its owner. sslcertificates.io is not a partner or certified reseller unless a written agreement exists.

Capabilities

login group_mapping sso_enforcement logout break_glass

Connect

Create an account to connect

Generic OpenID Connect is a trademark of its owner. sslcertificates.io is not a partner or certified reseller unless a written agreement exists.