Turn On Organization Sign-In
Organization sign-in is turned on per service and takes effect with the next deployment. The platform registers the application in the organization's IAM on its own — there is no client to request from anyone.
Before You Begin
- The service is a web application with Zero's public address.
- The organization has its IAM connected to Zero (it is the sign-in you use in the console).
- You can change the service in the project.
- The console does not have the screen yet: use the CLI (or the API).
Step by Step
-
Turn the capability on:
zero services enable organization-iam webThe response shows the state, the sign-in return address and the next step.
-
Follow it until Entra na próxima publicação (takes effect in the next deployment):
zero services capabilities web -
Deploy:
zero deploy web -
Check it end to end:
zero services doctor organization-iam webEach check comes out with ✓ or ✗ and, when something is missing, who fixes it: the application, the organization administrator or the platform. While something is missing, the command exits with code 3.
-
In your code, read who signed in with
nn.auth.user(req)— see Who Signed In, in Your Code.
To turn it off, zero services disable organization-iam web: sign-in leaves with the next deployment and the platform removes the application's registration from the IAM.
The States
| State (as shown) | What it means | What to do |
|---|---|---|
| Desligada (off) | the capability is not on | — |
| Registrando no IAM da organização (registering) | the platform is registering the application | wait |
| Falta configurar na plataforma (missing platform setup) | the organization's IAM does not yet authorize application registration — once per organization | ask the platform administrator; registration continues on its own afterwards |
| O IAM recusou o registro (the IAM refused the registration) | the reason comes with it | fix the reason and turn it on again |
| Entra na próxima publicação (next deployment) | everything is ready | zero deploy |
| Pronta (ready) | the deployment in service requires sign-in | — |
| Sai na próxima publicação (leaves with the next deployment) | turned off, with the deployment in service still requiring sign-in | zero deploy |
Common Errors
| Symptom | Cause | What to do |
|---|---|---|
ORGANIZATION_IAM_NOT_CONFIGURED when turning it on | the organization does not have its IAM connected to Zero | ask the platform administrator to connect the organization's IAM |
SERVICE_CAPABILITY_UNSUPPORTED when turning it on | the service is not a web application or has no public address | turn it on in the web service that receives people |
| Falta configurar na plataforma does not change | application registration has not been authorized for the organization yet | ask the platform administrator; there is no need to turn it on again |
| the application sees no one after sign-in | the deployment in service predates the capability | zero deploy and check with zero services doctor |
ORGANIZATION_IAM_NOT_ENABLED in the application log | the application ran without the capability, or outside Zero | turn the capability on and deploy |
Next Steps
Was this page helpful?
Report a problem on this pageDo not send passwords, keys, tokens, or customer data.