Thanks for taking the time to write this up @Ali Ardestani. I wanted to let you know that this is a conscious design decision. Enabling OIDC changes the way the account is accessed and if there’s a misconfiguration it will lock you out of your account. The manual enablement allows us to verify that the integration works by logging you back in using OIDC before we make the switch. This way we make sure that at least one person can access the account using the new IdP provider. This is not a guarantee we could offer if the entire process was API-driven.
Log in to comment and vote
Comments1
Black Breeze
Jan 29
Thanks for taking the time to write this up @Ali Ardestani. I wanted to let you know that this is a conscious design decision. Enabling OIDC changes the way the account is accessed and if there’s a misconfiguration it will lock you out of your account. The manual enablement allows us to verify that the integration works by logging you back in using OIDC before we make the switch. This way we make sure that at least one person can access the account using the new IdP provider. This is not a guarantee we could offer if the entire process was API-driven.