> AI agents: this is one page from PostHog's docs. Full index of Markdown docs for LLMs: https://posthog.com/llms.txt # OIDC ###### Where is this feature available? ##### Free / Open-source ##### Paid ##### Boost ##### Scale ##### Enterprise ![Not available](data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSIyMCIgaGVpZ2h0PSIyMCIgZmlsbD0ibm9uZSIgdmlld0JveD0iMCAwIDIwIDIwIj48cGF0aCBmaWxsPSIjRkI0RjBEIiBmaWxsLXJ1bGU9ImV2ZW5vZGQiIGQ9Ik0xMC4wNjQyIDcuODE5Nkw0LjI0NDU5IDJMMiA0LjI0NDU5TDcuODE5NiAxMC4wNjQyTDIuMTI4MzcgMTUuNzU1NEw0LjM3Mjk2IDE4TDEwLjA2NDIgMTIuMzA4OEwxNS40Njc1IDE3LjcxMjFMMTcuNzEyMSAxNS40Njc1TDEyLjMwODggMTAuMDY0MkwxNy44NDA1IDQuNTMyNDhMMTUuNTk1OSAyLjI4Nzg5TDEwLjA2NDIgNy44MTk2WiIgY2xpcC1ydWxlPSJldmVub2RkIi8+PC9zdmc+)![Not available](data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSIyMCIgaGVpZ2h0PSIyMCIgZmlsbD0ibm9uZSIgdmlld0JveD0iMCAwIDIwIDIwIj48cGF0aCBmaWxsPSIjRkI0RjBEIiBmaWxsLXJ1bGU9ImV2ZW5vZGQiIGQ9Ik0xMC4wNjQyIDcuODE5Nkw0LjI0NDU5IDJMMiA0LjI0NDU5TDcuODE5NiAxMC4wNjQyTDIuMTI4MzcgMTUuNzU1NEw0LjM3Mjk2IDE4TDEwLjA2NDIgMTIuMzA4OEwxNS40Njc1IDE3LjcxMjFMMTcuNzEyMSAxNS40Njc1TDEyLjMwODggMTAuMDY0MkwxNy44NDA1IDQuNTMyNDhMMTUuNTk1OSAyLjI4Nzg5TDEwLjA2NDIgNy44MTk2WiIgY2xpcC1ydWxlPSJldmVub2RkIi8+PC9zdmc+)![Not available](data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSIyMCIgaGVpZ2h0PSIyMCIgZmlsbD0ibm9uZSIgdmlld0JveD0iMCAwIDIwIDIwIj48cGF0aCBmaWxsPSIjRkI0RjBEIiBmaWxsLXJ1bGU9ImV2ZW5vZGQiIGQ9Ik0xMC4wNjQyIDcuODE5Nkw0LjI0NDU5IDJMMiA0LjI0NDU5TDcuODE5NiAxMC4wNjQyTDIuMTI4MzcgMTUuNzU1NEw0LjM3Mjk2IDE4TDEwLjA2NDIgMTIuMzA4OEwxNS40Njc1IDE3LjcxMjFMMTcuNzEyMSAxNS40Njc1TDEyLjMwODggMTAuMDY0MkwxNy44NDA1IDQuNTMyNDhMMTUuNTk1OSAyLjI4Nzg5TDEwLjA2NDIgNy44MTk2WiIgY2xpcC1ydWxlPSJldmVub2RkIi8+PC9zdmc+)![Available](data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSIyOCIgaGVpZ2h0PSIyOCIgZmlsbD0ibm9uZSIgdmlld0JveD0iMCAwIDI4IDI4Ij48cGF0aCBmaWxsPSIjNzFBQTU1IiBkPSJNOS41MTAwMyAyNC4wMjk5TDAuNDEwMDMzIDE0LjkyOTlDLTAuMTM2Njc4IDE0LjM4MzIgLTAuMTM2Njc4IDEzLjQ5NjggMC40MTAwMzMgMTIuOTVMMi4zODk4OCAxMC45NzAxQzIuOTM2NiAxMC40MjMzIDMuODIzMDggMTAuNDIzMyA0LjM2OTc5IDEwLjk3MDFMMTAuNSAxNy4xMDAyTDIzLjYzMDIgMy45NzAwOUMyNC4xNzY5IDMuNDIzMzggMjUuMDYzNCAzLjQyMzM4IDI1LjYxMDEgMy45NzAwOUwyNy41ODk5IDUuOTVDMjguMTM2NyA2LjQ5NjcxIDI4LjEzNjcgNy4zODMxNCAyNy41ODk5IDcuOTI5OUwxMS40ODk5IDI0LjAzQzEwLjk0MzIgMjQuNTc2NyAxMC4wNTY3IDI0LjU3NjcgOS41MTAwMyAyNC4wMjk5VjI0LjAyOTlaIi8+PC9zdmc+)![Available](data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSIyOCIgaGVpZ2h0PSIyOCIgZmlsbD0ibm9uZSIgdmlld0JveD0iMCAwIDI4IDI4Ij48cGF0aCBmaWxsPSIjNzFBQTU1IiBkPSJNOS41MTAwMyAyNC4wMjk5TDAuNDEwMDMzIDE0LjkyOTlDLTAuMTM2Njc4IDE0LjM4MzIgLTAuMTM2Njc4IDEzLjQ5NjggMC40MTAwMzMgMTIuOTVMMi4zODk4OCAxMC45NzAxQzIuOTM2NiAxMC40MjMzIDMuODIzMDggMTAuNDIzMyA0LjM2OTc5IDEwLjk3MDFMMTAuNSAxNy4xMDAyTDIzLjYzMDIgMy45NzAwOUMyNC4xNzY5IDMuNDIzMzggMjUuMDYzNCAzLjQyMzM4IDI1LjYxMDEgMy45NzAwOUwyNy41ODk5IDUuOTVDMjguMTM2NyA2LjQ5NjcxIDI4LjEzNjcgNy4zODMxNCAyNy41ODk5IDcuOTI5OUwxMS40ODk5IDI0LjAzQzEwLjk0MzIgMjQuNTc2NyAxMC4wNTY3IDI0LjU3NjcgOS41MTAwMyAyNC4wMjk5VjI0LjAyOTlaIi8+PC9zdmc+) OpenID Connect (OIDC) enables users to access multiple systems with a single set of credentials. This is helpful for growing organizations that require centralized user management in an Identity Provider (IdP). ## Prerequisites 1. If you are using PostHog cloud, your organization must be subscribed to a platform package that offers OIDC. If you are self-hosting PostHog, your instance must have an enterprise license that supports OIDC. 2. You need to [verify domains](/docs/settings/authentication/sso.md#authentication-domains) for any email address that you want to allow users to login with. For example, if you want to allow users with an `@example.com` email address to login, like `john@example.com`, you need to add and verify `example.com` as an authentication domain. 3. If you are self-hosting PostHog, make sure you have properly set up your `SITE_URL` [environment variable](/docs/self-host/configure/environment-variables.md) configuration. 4. If you are self-hosting PostHog, your PostHog instance must be accessible from the public internet over TLS. ## Configuring OIDC 1. Navigate to your organization's [authentication settings](https://app.posthog.com/settings/organization-authentication#setting=oidc-configuration) page in PostHog. 2. Scroll down to the **OIDC** section, and select **Configure**. 3. In your IdP, create a new OIDC app for PostHog. a. Copy the "*Redirect URL*" displayed in PostHog into your OIDC app's configuration in your IdP. b. Copy the "*Issuer URL*", "*Client ID*", "*Client Secret*" fields from your OIDC app's configuration in your IdP into the configuration fields in PostHog. If you do not see "*Issuer URL*" in your IdP, it will be the domain you use to login to the IdP, prefixed by `https://`. c. Verify that your IdP shares the `email` and `email_verified` OpenID claims with PostHog. Without these claims, PostHog cannot associated your users with their email address. 4. Select **Save**. ### Example: Okta 1. In Okta admin, go to **Applications** and select **Create App Integration**. ![Okta admin UI showing a Create App Integration button](https://res.cloudinary.com/dmukukwp6/image/upload/q_auto,f_auto/2026_09_17_okta_oidc_step_1_9a8193d241.png) 2. Select the **OIDC - OpenID Connect** option for sign-in method. For application type, select **Web Application**. ![Okta admin UI showing a modal to configure an app integration](https://res.cloudinary.com/dmukukwp6/image/upload/q_auto,f_auto/2026_09_17_okta_oidc_step_2_ba4ee97c1f.png) 3. Select **Next** and name the configuration *PostHog*. ![Okta admin UI showing a Create App Integration button](https://res.cloudinary.com/dmukukwp6/image/upload/q_auto,f_auto/2026_09_17_okta_oidc_step_3_8db0646163.png) 4. Navigate to your PostHog organization's [authentication settings](https://app.posthog.com/settings/organization-authentication#setting=oidc-configuration), scroll down to **OIDC**, then select **Configure**. ![Okta admin UI showing a Create App Integration button](https://res.cloudinary.com/dmukukwp6/image/upload/q_auto,f_auto/2026_09_17_okta_oidc_step_4_light_4a7b75e712.png) 5. Copy the *Redirect URL* from PostHog into the Okta app's *Sign-in redirect URIs* field. ![Okta admin UI showing OIDC app integration configuration](https://res.cloudinary.com/dmukukwp6/image/upload/q_auto,f_auto/2026_09_17_okta_oidc_step_4_4429ffadb8.png) 6. In Okta, choose which users to assign to the application, then select **Save**. ![Okta admin UI showing OIDC app integration configuration](https://res.cloudinary.com/dmukukwp6/image/upload/q_auto,f_auto/2026_09_17_okta_oidc_step_6_pt_2_f2219f971b.png) 7. Copy the **Client ID** and **Client Secret** from Okta into the configuration fields in PostHog. ![Okta admin UI showing OIDC client credential details](https://res.cloudinary.com/dmukukwp6/image/upload/q_auto,f_auto/2026_09_17_okta_oidc_step_6_07034d5cf5.png) 8. Enter your Okta instance's domain as the **Issuer URL** in PostHog. ![Okta admin UI showing OIDC client credential details](https://res.cloudinary.com/dmukukwp6/image/upload/q_auto,f_auto/2026_09_17_okta_oidc_step_7_light_2751d6d6ef.png) 9. Select **Save configuration** in PostHog. The next time you enter your email address during login, you will see an option to login using OIDC. ## Warnings When using OIDC to authenticate users in PostHog, there are a few considerations to keep in mind: 1. **Only use OIDC with identity providers you trust and that verify the user's email address.** During login we use the email address provided by the identity provider. An untrusted identity provider could spoof a user's email address to impersonate your users. 2. Enabling or enforcing **OIDC will not disable Personal API Key usage**. Users can authenticate with the PostHog API using their API keys without first authenticating via OIDC. You can use [ID-JAG (XAA)](/docs/settings/authentication/id-jag.md) to programmatically restrict API access using policies defined in your identity provider. 3. Our OIDC integration only handles authentication and user provisioning. It does not handle user removal. You can use [SCIM](/docs/settings/authentication/scim.md) to automatically deprovision users. 4. When you enable or enforce OIDC, any existing user passwords are saved. If you disable OIDC SSO in the future, your users will be able to login using their pre-existing password credentials. ### Still have questions? Ask PostHog AI ### Was this page useful? HelpfulCould be better