Docs

Identity providers

  • OIDC (all editions, one provider in Community): Authorization Code + PKCE. Tested with Authentik, Okta, Entra ID, Keycloak, AD FS. Group claims map to Janus groups and teams.
  • SCIM 2.0 (Business): users, groups and teams provisioned from the IdP; deprovisioning revokes access and keys.
  • LDAP / Active Directory (Business): bind authentication with group-to-team mapping.
  • Local accounts (all editions): password policy, TOTP MFA, intended for labs and the admin break-glass account so an IdP outage cannot lock administrators out.
  • Multiple OIDC providers (Business): several IdPs side by side with per-provider mapping.

Detailed provider walkthroughs live in the in-product docs under Admin → Identity.