Skip to main content
Open Settings → Sidekick → Auth to control how people sign in to Sidekick. You can run a single provider or several at once, and you can turn each one off later as your setup matures.
At least one auth provider must stay enabled at all times. Sidekick won’t let you turn off the last remaining provider, since that would lock everyone out.

Password

Password sign-in is on by default. Turn it off once you’ve set up SSO and want to require people to sign in through your identity provider instead.

Social and enterprise SSO

Social sign-in through Google works in two modes:
  • Oximy-managed: uses a shared Google app Oximy already operates. Turn it on and there’s nothing further to configure.
  • Company-owned: uses your own Google app instead of the shared one. Enter:
    • Client ID
    • Client secret
    • Routed email domains: the domains that should be sent through this app.
Company-owned is the right choice when you want sign-in attributed to an app your own company controls.
Secrets, such as client secrets, are write-only. Once saved, Sidekick won’t display the value again; to change it, enter a new one.

Where to go next

Directory sync

Keep who has Sidekick login access in sync with your identity provider automatically.