You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit b6cda06
Browse filesBrowse the repository at this point in the historyBrowse files
You can register providers through the **Settings UI** (same as cloud) or by running the registration script directly against your database.
421
421
422
+
Restricted networks can opt out of the DNS challenge with the server-only `SSO_SKIP_DOMAIN_VERIFICATION=true` setting. Add the domain and click **Verify** before saving SSO. This trusts administrator claims across the instance and is ignored on Sim Cloud. See [skipping DNS verification](/platform/enterprise/verified-domains#skip-dns-verification) for the trust implications and [DNS network requirements](/platform/enterprise/verified-domains#restricted-networks) for the default setup.
423
+
422
424
### Script-based registration
423
425
424
426
Use this when you need to register an SSO provider without going through the UI — for example, during initial deployment or CI/CD automation.
Copy file name to clipboardExpand all lines: apps/docs/content/docs/platform/enterprise/verified-domains.mdx
+29-1Lines changed: 29 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -67,7 +67,7 @@ Add each domain you own separately. Subdomains (`eng.acme.com`) are verified ind
67
67
68
68
## Self-hosted setup
69
69
70
-
Domain verification has no flag of its own. It lives on the single sign-on page, so it appears exactly when SSO does:
70
+
Domain verification appears on the single sign-on pagewhen SSO is enabled:
71
71
72
72
```bash
73
73
SSO_ENABLED=true
@@ -77,3 +77,31 @@ NEXT_PUBLIC_SSO_ENABLED=true
77
77
`ENTERPRISE_ENABLED` turns both on together, but it needs its own browser twin — set `NEXT_PUBLIC_ENTERPRISE_ENABLED` alongside it, or the server and the settings page enable SSO while the login page still hides its SSO entry point. See the [self-hosted enterprise guide](/platform/enterprise/self-hosted).
78
78
79
79
Once enabled, verify domains from **Settings → Organization → Single sign-on → Domains**. The older `/workspace/<workspaceId>/settings/domains` path still resolves to the same page.
80
+
81
+
### Restricted networks
82
+
83
+
Sim queries `1.1.1.1` and `8.8.8.8` directly from the application server. Allow outbound DNS on UDP and TCP port 53 to these addresses. The lookup uses public DNS rather than the server's local resolver or an HTTP proxy, so the TXT record must be published in a publicly delegated DNS zone. A Route 53 private hosted zone is not visible to these resolvers.
84
+
85
+
### Skip DNS verification
86
+
87
+
For a deployment where the operator trusts every organization owner and admin to claim email domains, set this server-only variable and restart the application:
88
+
89
+
```bash
90
+
SSO_SKIP_DOMAIN_VERIFICATION=true
91
+
```
92
+
93
+
For Helm deployments, set it in your values file:
94
+
95
+
```yaml
96
+
app:
97
+
env:
98
+
SSO_SKIP_DOMAIN_VERIFICATION: "true"
99
+
```
100
+
101
+
Add the domain under **Domains**, then click **Verify**. No TXT record or DNS access is needed. The domain is recorded as verified for SSO account linking and SCIM provisioning, and another organization still cannot claim the same domain. Existing pending domains can be verified the same way.
102
+
103
+
<Callout type="warn">
104
+
This option is off by default and ignored on Sim Cloud. It applies to every organization in the self-hosted instance: an organization administrator can authorize their identity provider for any unclaimed email domain without proving ownership. Enable it only when those administrators are trusted to make that decision.
105
+
</Callout>
106
+
107
+
Removing the variable or setting it to `false` restores DNS verification for pending and future claims. Domains already verified remain verified; remove a domain in **Domains** to revoke its trust.
Copy file name to clipboardExpand all lines: apps/docs/content/docs/platform/self-hosting/environment-variables.mdx
+1Lines changed: 1 addition & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -248,6 +248,7 @@ Enterprise features are unlocked by configuration rather than billing on self-ho
248
248
|----------|-------------|
249
249
|`ENTERPRISE_ENABLED`, `NEXT_PUBLIC_ENTERPRISE_ENABLED`| Enable the whole enterprise feature set |
250
250
|`SSO_ENABLED`, `NEXT_PUBLIC_SSO_ENABLED`| Enable SAML and OIDC single sign-on on its own. See [Authentication](/platform/self-hosting/authentication#sso-saml-and-oidc)|
251
+
|`SSO_SKIP_DOMAIN_VERIFICATION`| Skip the DNS challenge when an administrator clicks Verify on a domain. Off by default; self-hosted only. Trusts administrator claims for SSO and SCIM across the instance. See [Verified Domains](/platform/enterprise/verified-domains#skip-dns-verification)|
251
252
|`SCIM_ENABLED`, `NEXT_PUBLIC_SCIM_ENABLED`| Enable directory provisioning on its own. Needs SSO. See [Directory provisioning](/platform/enterprise/scim)|
252
253
|`INSTANCE_ORG_NAME`| Name of the organization every user joins automatically at signup |
253
254
|`INSTANCE_ORG_SLUG`| Slug for that organization (derived from the name when omitted) |
"We couldn't complete the DNS lookup, so we can't tell yet whether your record is published. Try again in a few minutes — if it keeps failing, check that your domain's nameservers are responding."
239
-
)
240
-
if(lookup==='absent')
241
-
thrownewDomainVerificationLookupError(
242
-
422,
243
-
'The verification TXT record was not found yet. DNS changes can take up to 48 hours to propagate — add the record shown and try again.'
"We couldn't complete the DNS lookup, so we can't tell yet whether your record is published. Try again in a few minutes — if it keeps failing, check that your domain's nameservers are responding."
244
+
)
245
+
if(lookup==='absent')
246
+
thrownewDomainVerificationLookupError(
247
+
422,
248
+
'The verification TXT record was not found yet. DNS changes can take up to 48 hours to propagate — add the record shown and try again.'
Copy file name to clipboardExpand all lines: helm/sim/values.schema.json
+4Lines changed: 4 additions & 0 deletions
Original file line number
Diff line number
Diff line change
@@ -167,6 +167,10 @@
167
167
"type": "string",
168
168
"description": "Comma-separated CIDRs or IPs on a private network that outbound requests may reach (e.g. '10.0.0.0/8'). Cloud metadata endpoints stay blocked regardless. Ignored on the hosted platform."
169
169
},
170
+
"SSO_SKIP_DOMAIN_VERIFICATION": {
171
+
"type": "string",
172
+
"description": "Set to 'true' to trust organization administrator domain claims without DNS proof on self-hosted deployments. Off by default and ignored on Sim Cloud."
173
+
},
170
174
"SSO_TRUSTED_PROVIDER_IDS": {
171
175
"type": "string",
172
176
"description": "Comma-separated SSO provider IDs to trust for automatic account linking when an SSO sign-in matches an existing account's email. Only needed for IdPs that do not assert email_verified. Merged into Better Auth accountLinking.trustedProviders."
0 commit comments