From 74a76c56076f65c6ffcf94176dcb95b45c05aedc Mon Sep 17 00:00:00 2001 From: Maximilian Kaske Date: Thu, 1 Oct 2026 22:05:26 +0200 Subject: [PATCH] fix: content --- apps/web/src/content/pages/changelog/saml-sso.mdx | 4 +--- .../src/content/pages/docs/guides/how-to-set-up-saml-sso.mdx | 2 +- apps/web/src/content/pages/unrelated/security.mdx | 2 +- 3 files changed, 3 insertions(+), 5 deletions(-) diff --git a/apps/web/src/content/pages/changelog/saml-sso.mdx b/apps/web/src/content/pages/changelog/saml-sso.mdx index 4a978518..d05fc284 100644 --- a/apps/web/src/content/pages/changelog/saml-sso.mdx +++ b/apps/web/src/content/pages/changelog/saml-sso.mdx @@ -11,9 +11,7 @@ Your team can now sign in to openstatus through your own identity provider. **Ok Head to **Settings > SSO**, enable it, and verify your domain with a DNS TXT record. Verification is not optional: openstatus only accepts an SSO sign-in when the email your identity provider asserts belongs to a domain you own. Then connect your provider and you're done. -On the login page your team selects **Sign in with SSO** and enters their work email — they're redirected to your identity provider and added to the workspace as members on first login. Signing in from your provider's app tile works too. Anyone who already has an openstatus account with the same email keeps it, along with their role. - -_Edit: there is no separate SSO button anymore. Enter your work email and click **Continue** — a verified SSO domain is sent to your identity provider, any other address receives a magic link._ +On the login page your team selects **Continue with SSO** and enters their work email — they're redirected to your identity provider and added to the workspace as members on first login. Signing in from your provider's app tile works too. Anyone who already has an openstatus account with the same email keeps it, along with their role. GitHub and Google stay available — SSO is an additional way in, not a replacement. diff --git a/apps/web/src/content/pages/docs/guides/how-to-set-up-saml-sso.mdx b/apps/web/src/content/pages/docs/guides/how-to-set-up-saml-sso.mdx index 86babaa3..22514c1d 100644 --- a/apps/web/src/content/pages/docs/guides/how-to-set-up-saml-sso.mdx +++ b/apps/web/src/content/pages/docs/guides/how-to-set-up-saml-sso.mdx @@ -41,7 +41,7 @@ When the connection goes live, the SSO page shows **Ready — your team can sign ## Signing in -On the login page your team enters their work email and clicks **Continue**. The domain is matched against your verified domains and they're redirected to your identity provider instead of receiving a magic link. +On the login page your team selects **Continue with SSO** and enters their work email. The domain is matched against your verified domains and they're redirected to your identity provider. An address whose domain isn't verified receives a magic link instead. Users signing in this way are added to your workspace automatically as **members** on first login. Someone who already has an openstatus account with the same email keeps that account, along with any role they already hold — an existing owner stays an owner. diff --git a/apps/web/src/content/pages/unrelated/security.mdx b/apps/web/src/content/pages/unrelated/security.mdx index cff073bb..809448a5 100644 --- a/apps/web/src/content/pages/unrelated/security.mdx +++ b/apps/web/src/content/pages/unrelated/security.mdx @@ -46,7 +46,7 @@ Application secrets — third-party tokens, webhook URLs, integration credential ## Authentication and access -You sign in with GitHub or Google OAuth. We never see or store your password. +You sign in with GitHub or Google OAuth, an email magic link, or your company's SSO provider. openstatus has no passwords to see or store. API access uses scoped keys: a key with the `read` scope can only call read-only endpoints; a key with the `write` scope can mutate data. Scopes are enforced before any database lookup, so a read-only key can't even reach a write code path. -- 2.51.2