Set up access and apps

Single sign-on

How signing in to the Cockpit works, what to do when it fails, and why your buyers log in somewhere else entirely.

You are already using single sign-on. There is no separate Cockpit password and no Cockpit login form. Opening the Cockpit hands you to Revenexx SSO, the revenexx identity provider, and it hands you back with a session.

What that means in practice

One account, one sign-in. The identity provider issues your session for the Cockpit and for the other revenexx services you have access to. Sign out in one place and the session is gone.

Your password lives with the identity provider. You set it when you accept your invitation and change it under Settings › Profile › Security. Nobody at your company and nobody at revenexx can read it.

Access is granted by being a member. Somebody who has not been invited to your organisation cannot sign in, no matter that they have a valid revenexx account. Invitations are handled in Settings › Team; see Users, roles and permissions.

Add a second factor. Single sign-on concentrates access in one credential, which is exactly why that credential should not be a password alone. Enrol a passkey or an authenticator app; see Security and data protection.

When sign-in fails

The failure page says Sign-in failed. We couldn't establish a session with Revenexx SSO. In practice it is one of three things, in the order worth checking:

SymptomUsual causeFix
A colleague who has never signed in gets the failure pageThe account is not provisioned for the CockpitCheck they appear under Settings › Team; re-invite if not
Someone who signed in yesterday gets it todayThe session was rejected, usually a stale or partial browser sessionSign out fully, clear the site's cookies, try again in a private window
Everyone gets it at onceAn identity-provider problemDo not re-invite anybody. Raise it with support

The one thing not to do is create a second account for the same person. You end up with duplicate members, split activity, and a suspended account that is not the one being used.

Connecting your own directory

Mittelstand companies usually run Active Directory or Microsoft Entra ID and would prefer their team not to have another identity at all. Federating your directory with Revenexx SSO is possible: the identity provider speaks SAML and OIDC, and a federated sign-in means your colleagues authenticate with your directory and arrive in the Cockpit without a second password.

Self-service federation setup: planned. There is no SSO settings screen in the Cockpit and no domain verification flow. Today, federation is a project with your revenexx contact and your own IT rather than a setting you switch on. Bring the directory you use, the protocol your IT prefers, and whether you also want automatic provisioning and deprovisioning of members. Nothing you set up in Settings › Team is lost when federation lands; membership stays the thing that grants access.
Your buyers do not use this. The people who buy from you sign in to your storefront with credentials managed under CRM › Contacts and configured under Settings › Auth & Security (titled Auth & Security · Customers), including any third-party sign-in providers you offer them on its OAuth tab. That is a separate authentication system. Enabling something there changes nothing for your team, and vice versa. See Contacts and roles.

What to check

Ask a colleague to sign in from a device they have never used. They should reach the Cockpit without you doing anything. If they hit the failure page, the account is not provisioned. Start at Settings › Team.

Next