new·The score now tells you which way it movedA brain's exam only ever grows: its own material writes questions, and so does every question a real caller asked and did not get answered. The score is a percentage over that growing set, so a brain that learned more could post a smaller number — and this week three did. One of them answered two MORE questions than the week before and showed eighteen points less. Printed as a single percentage, that reads as decline to a reader and as punishment to anyone who contributes material.all news →
mozg.beta
Sign in

Expo & React Native · all subjects

sso

18 notes, read out of this brain and free to use. Each one was extracted from a source and is re-checked against its exam.

SSO availability and plan requirements

Single Sign-On (SSO) is available only for Production and Enterprise plan customers.

Supported SSO identity providers

Expo SSO supports Okta, OneLogin, Microsoft Entra ID, and Google Workspace. Expo implements the OpenID Connect Discovery 1.0 specification and is working to verify additional compatible identity providers.

Organization SSO setup location

To set up SSO for an organization, log in as the Organization account owner and navigate to Settings > Organization settings > Create SSO configuration for account in the EAS dashboard.

SSO configuration required information

When configuring SSO, you must enter the following details from your identity provider: Client ID, Client secret, and IdP subdomain/tenant ID if needed. Help is available via the ? icon above the Issuer field.

Required non-SSO owner for SSO organizations

Organization accounts that enable SSO must maintain at least one non-SSO user with the Owner role. This user is required for initial SSO setup and to ensure uninterrupted access if SSO configuration changes or SSO is discontinued.

SSO login via website

SSO users can log in at expo.dev/sso-login by entering their organization account name. The URL can be pre-filled with the organization name, for example expo.dev/sso-login/test-org. Users then log in to their identity provider and select an Expo username for their account.

SSO login via Expo CLI

To log in via SSO using the Expo CLI, run: npx expo login --sso, yarn expo login --sso, pnpm expo login --sso, or bun expo login --sso. You will be prompted to log in via the Expo website in a browser and will be redirected back to the CLI upon completion.

SSO login via EAS CLI

To log in via SSO using the EAS CLI, run: eas login --sso. You will be prompted to log in via the Expo website in a browser and will be redirected back to the CLI upon completion.

SSO login via Expo Go

To sign in via SSO in Expo Go, click the Continue with SSO button on the sign-in page, then follow the steps to sign in to the Expo website.

SSO user restrictions

SSO users have the following restrictions: they can only belong to their SSO organization and cannot create additional organizations, they cannot leave their SSO organization (doing so deletes their SSO user), they cannot log in to the Expo forums, and they cannot subscribe to EAS for their personal accounts.

Converting regular users to SSO users

Regular users cannot be directly converted to SSO users because SSO users belong exclusively to their organization while regular users may belong to multiple accounts. However, a regular user who is a member of an organization can create a second SSO user via the SSO login page, after which their regular user can be removed from the organization.

Default role for new SSO users

New SSO users are assigned the View Only role by default. An Admin or Owner can update the role in the Members settings if a different role is needed.

Removing SSO users from organization

To remove an SSO user from an organization, navigate to the organization account Members settings, click the dropdown next to the member, and click Delete SSO user. This will delete the user's personal account and all associated data, but data in the organization account remains unaffected.

Disabling access for removed SSO users

When an SSO user is removed or disabled in the identity provider, they will lose access to their Expo account based on the token refresh duration configured with the IdP. Users can also be manually removed from the organization Members settings page.

SSO organization deletion

Once SSO is configured for an organization, account deletion must be done manually by the Expo team. Contact us for assistance.

Plan requirements for SSO continuation

An active Production or Enterprise Plan is required to continue using SSO. Contact Expo if you wish to discontinue SSO or change your plan.

External contributors in SSO organizations

SSO-enabled organizations can invite additional non-SSO users via email to support external contributors, while existing SSO users continue with their current credentials.

Updating SSO configuration

After initial SSO setup, the Organization settings > Overview page displays an Update SSO configuration option that can be used to update the client secret if it changes.

Give your agent this brain