[PB-49692] As a CE user, I should be able to use SSO

Q1. What is the problem that you are trying to solve?
I’m trying to make it clear that SSO is NOT a pro feature, but rather basic functionality of an app.

Q2 - Who is impacted?
Everyone not using PRO version

Q3 - Why is it important and/or urgent?
It’s very important

Q4 - What is your proposed solution? (optional)

I would add support for OpenID Connect and include it in community version.

Q5. Community support

People can vote for this idea to show traction:

  • :ok_woman: Must have: this is critical for me to have this
  • :raising_hand_woman: Should have: this is important for me to have this
  • :tipping_hand_woman: Could have: this could be nice to have
  • :no_good_woman: Won’t have: we should not schedule this (explain why)
0 voters
3 Likes

Hi,

I added the poll :smiley:

1 Like

Would be really great. And could integrate it with my Keycloak. Its doing SSO for all my self-hosted apps.

2 Likes

Hello @Kofl and welcome to the forum!
This is already possible with the OpenID option added recently, but SSO is a PRO feature so you will need to ask for the PRO version or wait until the team release the feature to CE version
image

Thus making it NOT AVAILABLE. :slight_smile:

OpenID and OpenID Connect I don’t think are the same thing and SSO shouldn’t be considered a PRO feature but rather basic features of an app.

6 Likes

So this still isn’t available in CE, right?

Hi Alex.

Not currently, no.

The reference for what’s included in CE/PRO.
https://www.passbolt.com/pricing/pro

Pro features:

Single Sign On (SSO) with Microsoft			
Single Sign On (SSO) with Google			
Single Sign On (SSO) with OpenID			
Single Sign On (SSO) with AD FS

Cheers
Gareth

1 Like

It’s just a shame we can’t even use OIDC in the CE

(Thanks for the quick reply btw)

1 Like

Or, for the SSO feature, Passbolt should charge a small fee—around $50 per month—to enable it.

Signed up just to vote and express my interest in this being a feature. We’re currently using Vaultwarden for my selfhosted community. I don’t think we’ll switch to Passbolt CE until SSO through OpenID is made accessible. Not that our community is particularly valuable or anything, but this is no longer a feature that’s only used by corporations.

Related: https://sso.tax

1 Like

bump.. I mean come on… I was so disappointed as I was getting ready to switch from cloud to a self hosted password manager when I realized I couldn’t use my self hosted keycloak sso…… any password I can think of is deemed mediocre according to the passbolt password grader – and I’m supposed to trust the rest of my household to have decent passwords? lol

1 Like

Bump because openID should be open, and basic sso is better than a weak human master pass; a user account limit should be enough to have it in the CE build :wink: without harming pro subscriber counts

1 Like

Hello just tried Passbolt CE and, it looks great !

But without SSO (i’m using Keycloak) it will be a no-go for me. Sad.

1 Like

I’ll add my 2 cents to this request: while I understand the legitimate need of Passbolt to build a viable business, I believe that adding SSO support to the CE edition while limiting its use to “family & friends” scenarios (for example, max. 10 users) would not jeopardize the company’s viability while sustaining a thriving community. Please Passbolt, consider this option seriously: SSO is necessary for any serious password management solution, not only for professionals, but also for families. Thanks!

3 Likes