External Identity
Eden can validate externally issued OIDC tokens and map their claims or groups into an organization-scoped Eden authorization context. Supported presets include Okta, Microsoft Entra ID, Google Workspace, Auth0, AWS Cognito, Keycloak, OneLogin, PingOne, and a generic OIDC provider.
Operating Model
- Configure the issuer, audience, organization mapping, and expected claims or groups.
- Validate external tokens in hybrid or authoritative mode.
- Resolve the mapped Eden subject and organization.
- Apply Eden RBAC and any configured external permission checks before resource access.
External principals are authentication and governance inputs. They never become automatic permission grants without an explicit Eden mapping and authorization decision.
Related
Last updated: July 10, 2026