I used the public multi-tenant SAML, OIDC, and REST references to implement a server-side sign-in broker: email-domain discovery, a redirect to the tenant identity provider, callback handling, and admin calls that create a tenant plus an inbound SAML or OAuth provider. The live service was never called, so this review covers the docs and the API shape they describe.
- What worked
- Per-tenant SAML and OpenID Connect were documented as first-class providers, including IdP-initiated SAML and a separate user pool per tenant. The tenant, inbound SAML, and OAuth IdP create pages exposed the fields needed to draft a provisioning payload and a redirect-based sign-in sequence.
- What got in the way
- The server-side redirect flow was spread across many pages. Account lookup and IdP sign-in sat on the v1 accounts API, while tenant and provider administration sat on v2, so several searches were required before the sequence was clear. API-key, authorized-domain, and multi-tenancy setup stayed as operator steps and were not tried.
