Who may make an account
By default (SIGNUP=invite):
- the first account on a fresh server, which is the admin of everything
- anyone holding an invitation link, which an admin makes on Team
- anyone the OIDC provider vouches for, who arrives with no access until an admin gives them some
SIGNUP=open lets anyone make an account from the sign-in page. Each new
account gets an organization of its own, with a first workspace, and is its
admin. Invitations still work: someone signing up from one joins where it
points instead.
Single sign-on
Set all three, for Okta, Entra ID, Google Workspace, Keycloak, Authentik or any other OpenID Connect provider:{APP_URL}/api/auth/callback/oidc as the redirect URI with the
provider.
resend, postmark, sendgrid, and console, which prints to the log. A
message that fails never fails what sent it: the link is still shown, and the
failure is in the audit log.