Docs
Identity providers
- OIDC (all editions, one provider in Community): Authorization Code + PKCE. Tested with Authentik, Okta, Entra ID, Keycloak, AD FS. Group claims map to Janus groups and teams.
- SCIM 2.0 (Business): users, groups and teams provisioned from the IdP; deprovisioning revokes access and keys.
- LDAP / Active Directory (Business): bind authentication with group-to-team mapping.
- Local accounts (all editions): password policy, TOTP MFA, intended for labs and the admin break-glass account so an IdP outage cannot lock administrators out.
- Multiple OIDC providers (Business): several IdPs side by side with per-provider mapping.
Detailed provider walkthroughs live in the in-product docs under Admin → Identity.