Surfil

Runbook: SSO & OIDC

Enterprises sign in through their own identity provider. Surfil supports OIDC single sign-on so access follows your directory - onboarding and offboarding a person in your IdP flows straight through to Surfil.

What SSO gives you

  • One identity - people sign in with your IdP; no separate Surfil password to manage.
  • Group-to-role mapping - map IdP groups to Surfil roles (owner / admin / member), so access is governed centrally.
  • Lifecycle - deprovisioning a user in your IdP removes their Surfil access.

Setup

SSO is configured per organization as part of enterprise onboarding: you register Surfil as an OIDC relying party in your IdP and provide the issuer and client details to your Surfil contact. Device tokens still use the device flow underneath - SSO governs the human account, device approval governs each machine.

SSO is an enterprise capability. Until it's configured for your org, sign-in uses the standard account flow. Configuration steps are shared during onboarding rather than self-serve today - this page states that honestly instead of guessing exact fields.