> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://help.simplyprint.io/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# Set up Auth0 single sign-on (OIDC) for SimplyPrint

# Set up Auth0 single sign-on (OIDC) for SimplyPrint

This guide walks you through connecting Auth0 to SimplyPrint using OpenID Connect (OIDC), so your members sign in to SimplyPrint with their Auth0 accounts. You'll create a web application in Auth0, copy three values across, and run a test sign-in to confirm everything works.

|| Single sign-on is included in the Enterprise plan and the School plan. Print Farm accounts that subscribed before 2026-05-15 keep SSO as well.

Auth0 also works over SAML. If you'd rather use that, see [Set up Auth0 single sign-on (SAML)](https://help.simplyprint.io/en/article/set-up-auth0-single-sign-on-sso-for-simplyprint-hmjdco/). Your account runs one SSO method at a time, so pick whichever your Auth0 admin prefers. Turning on OIDC deactivates SAML if you had it set up, but your SAML configuration is kept in case you switch back.

|| SimplyPrint has no dedicated Auth0 preset, so you'll use the **Other** preset. Auth0 is a standard OIDC provider, so this works the same as any other, you just paste in Auth0's issuer, client ID, and client secret.

New to SSO in SimplyPrint? Start with the [single sign-on overview](https://help.simplyprint.io/en/article/single-sign-on-sso-for-simplyprint-overview-and-setup-guides-16o3fy7/), which compares SAML and OIDC and links every setup guide.

## What you need before starting
- Admin access to your Auth0 tenant (the Auth0 Dashboard at manage.auth0.com).
- An account admin in SimplyPrint with the user registration settings permission.
- Your account on a plan that includes SSO (see the note above).

## Open the OIDC configuration in SimplyPrint
First, open SimplyPrint so you have the redirect URI ready to paste into Auth0.

1. Go to [Settings -> Organization](https://simplyprint.io/panel/settings/organization#registration) and open **User registration & SSO**.
2. Tick **OpenID Connect (OIDC) single sign-on**.
3. Click **Configure OIDC single sign-on**.
4. Select the **Other** tab at the top of the modal.

Under **What you need from us**, click **Copy** next to **Redirect URI**. Keep this window open, you'll paste this value into Auth0 next, then come back to finish.

||| Copy the exact Redirect URI shown in your own window. It is your SimplyPrint site address followed by `/oauth/callback`. Use the value from the modal rather than typing it by hand, it must match exactly or Auth0 will reject the sign-in.

## Create a web application in Auth0
In the Auth0 Dashboard:

1. Go to **Applications -> Applications**, then click **Create Application**.
2. Give it a name, for example "SimplyPrint".
3. Choose **Regular Web Applications** as the application type, then click **Create**.
4. Open the app's **Settings** tab. Note the **Domain**, **Client ID**, and **Client Secret** near the top, you'll need all three.
5. Scroll down to **Allowed Callback URLs** and paste the **Redirect URI** you copied from SimplyPrint.
6. Click **Save Changes**.

New Auth0 web applications are OIDC-conformant by default, so there's nothing else to toggle.

## Find your Auth0 issuer
SimplyPrint discovers the rest of the connection from your Auth0 **issuer**, which is your tenant domain as a URL:

https://your-tenant.us.auth0.com/

Replace `your-tenant.us.auth0.com` with the **Domain** from your app's Settings tab. If you use an Auth0 custom domain, use that instead.

||| Include the trailing slash. Auth0's issuer ends in a `/`, and SimplyPrint checks the issuer exactly, so copy it as your Domain with `https://` in front and a `/` at the end.

## Enter your Auth0 details in SimplyPrint
Back in the SimplyPrint OIDC window on the **Other** tab, under **What we need from you**:

1. In **Issuer URL**, paste your Auth0 issuer (for example https://your-tenant.us.auth0.com/).
2. Click **Check**. SimplyPrint fetches Auth0's discovery document and shows the resolved endpoints. A green "Discovery document looks good" message means the issuer is correct.
3. Paste your **Client ID**.
4. Paste your **Client Secret**. (Once a secret is saved it shows as "Unchanged", leave it blank on later edits to keep it, or enter a new one to replace it.)
5. Leave **Scopes** as `openid profile email` unless you need more.

Click **Save** when you're done.

## Map claims to user fields
The **Other** preset maps the standard OIDC claims: `email` to email, `given_name` to first name, and `family_name` to last name. Auth0 sends these on the `profile` and `email` scopes, so the defaults usually work as-is.

Auth0 does not send a groups claim by default. If you want to sort members into SimplyPrint user groups automatically, add a namespaced custom claim (for example `https://simplyprint.io/groups`) with an Auth0 **Action** on the login flow, then map that claim to **user groups** in SimplyPrint. The concept is the same as SAML group mapping, see the [group mapping guide](https://help.simplyprint.io/en/article/saml-single-sign-on-user-groups-group-mapping-and-teacher-mapping-lfgz7/).

## Test the connection
Before rolling this out to your members, use the built-in test.

1. Save your settings first.
2. Click **Test sign-in** in the OIDC window. This opens a new tab and runs the real Auth0 sign-in flow.
3. SimplyPrint shows you the claims Auth0 returned, without logging anyone in or creating an account.

Check that the email and name claims arrived as expected. This is the recommended way to verify the connection before going live.

## How sign-in and new accounts work
Once OIDC is active, members can sign in through Auth0. Existing SimplyPrint users can link their account, and new members can be created automatically on first sign-in.

A new account is created automatically only when the email address is trustworthy: Auth0 marked it as verified, the email's domain is one your account has verified, or an admin turned off **Require verified email** in the **Advanced** section. Auth0 database connections send a verified-email signal, so the default settings work for most tenants. If you ever see new members blocked from being created, verify your email domains, see [verifying your email domains](https://help.simplyprint.io/en/article/verify-your-email-domains-for-single-sign-on-g24cgc/).

When members sign out of SimplyPrint, they're also signed out at Auth0, because Auth0 advertises a logout endpoint.

For more on linking and signing in:
- [Link an existing SimplyPrint account to SSO](https://help.simplyprint.io/en/article/linking-your-existing-simplyprint-account-to-your-sso-account-5pw0aj/)
- [Sign in with SSO (organization login)](https://help.simplyprint.io/en/article/signing-in-with-sso-organization-login-1v0eb2h/)

## Troubleshooting
If sign-in fails, the OIDC window has two tools built in:
- The **Check** button validates your issuer and shows Auth0's endpoints. Start here if the connection won't save or test.
- The debug panel shows the last claims received (email addresses are masked) and the last error reported for your provider.

Common things to check:
- The **Redirect URI** registered in Auth0's **Allowed Callback URLs** exactly matches the one shown in SimplyPrint.
- The **issuer** is your Auth0 domain as a URL with a trailing slash, and **Check** returns a green result.
- The **Client ID** and **Client Secret** are from the same Auth0 app, with no extra spaces.

For a deeper checklist that applies to every provider, see the [OIDC troubleshooting guide](https://help.simplyprint.io/en/article/troubleshoot-openid-connect-oidc-sign-in-cyos2f/).

## Related articles
- [Single sign-on (SSO) overview and setup guides](https://help.simplyprint.io/en/article/single-sign-on-sso-for-simplyprint-overview-and-setup-guides-16o3fy7/)
- [Set up Auth0 single sign-on (SAML)](https://help.simplyprint.io/en/article/set-up-auth0-single-sign-on-sso-for-simplyprint-hmjdco/)
- [Set up OpenID Connect (OIDC) single sign-on for SimplyPrint](https://help.simplyprint.io/en/article/set-up-openid-connect-oidc-single-sign-on-for-simplyprint-1bypz64/)
- [Set up OIDC single sign-on with any identity provider](https://help.simplyprint.io/en/article/set-up-openid-connect-oidc-single-sign-on-with-any-identity-provider-yg318w/)
- [Verifying your email domains](https://help.simplyprint.io/en/article/verify-your-email-domains-for-single-sign-on-g24cgc/)
- [Troubleshooting OIDC single sign-on](https://help.simplyprint.io/en/article/troubleshoot-openid-connect-oidc-sign-in-cyos2f/)
