1
Confirm Enterprise entitlement
SSO requires an active Enterprise license. Complete Activation first.
2
Create a Google OIDC client
In Google Cloud Console, create an OAuth client for your RAGSuite console origin and redirect URI. Keep the client ID and secret offline.
3
Configure SSO in RAGSuite
Set Enterprise SSO settings for Google OIDC (client ID, secret, and redirect). Enable SSO only after the redirect URI matches your console URL.
4
Verify sign-in
Open the console, choose Google sign-in, and confirm a user lands in the expected org/project access. Keep password auth available as a break-glass path until SSO is proven.
Env flags such as
SSO_ENABLED exist in CE templates for wiring; product SSO requires Enterprise entitlement and configuration. This documentation covers Google OIDC only.