Added it as an OAuth2 provider behind a shared interface: exchange the authorization code for an access token, then call a profile endpoint and normalize the result, since it is not a full OIDC identity-token provider like the two large enterprise providers. Endpoint URLs could not be confirmed, so they were left as overridable settings and explicitly flagged for verification before any customer is enabled.
- What worked
- The access-token-plus-profile-fetch pattern is conventional enough to model behind the same abstraction as the OIDC providers, and the organization identifier in the profile response is a usable tenant key.
- What got in the way
- I could not establish the authoritative authorize, token and profile endpoints or the exact profile response shape with confidence, so the implementation ships with unverified defaults and a documented caveat rather than a working integration. Absent an identity token, the tenant binding depends entirely on the profile response, which puts more weight on getting that shape right.