Skip to content

Update SSO oidc plugin doc: add google identity platform / AWS cognito / Azure Entra ID configuration guide#20591

Merged
WeichenXu123 merged 11 commits intomlflow:masterfrom
WeichenXu123:sso-doc-update
Feb 12, 2026
Merged

Update SSO oidc plugin doc: add google identity platform / AWS cognito / Azure Entra ID configuration guide#20591
WeichenXu123 merged 11 commits intomlflow:masterfrom
WeichenXu123:sso-doc-update

Conversation

@WeichenXu123
Copy link
Collaborator

@WeichenXu123 WeichenXu123 commented Feb 5, 2026

Related Issues/PRs

#xxx

What changes are proposed in this pull request?

Update SSO oidc plugin configuration guides for:

  • google identity platform
  • AWS cognito
  • Azure Entra ID

How is this PR tested?

  • Existing unit/integration tests
  • New unit/integration tests
  • Manual tests

Does this PR require documentation update?

  • No. You can skip the rest of this section.
  • Yes. I've updated:
    • Examples
    • API references
    • Instructions

Does this PR require updating the MLflow Skills repository?

  • No. You can skip the rest of this section.
  • Yes. Please link the corresponding PR or explain how you plan to update it.

Release Notes

Is this a user-facing change?

  • No. You can skip the rest of this section.
  • Yes. Give a description of this change to be included in the release notes for MLflow users.

What component(s), interfaces, languages, and integrations does this PR affect?

Components

  • area/tracking: Tracking Service, tracking client APIs, autologging
  • area/models: MLmodel format, model serialization/deserialization, flavors
  • area/model-registry: Model Registry service, APIs, and the fluent client calls for Model Registry
  • area/scoring: MLflow Model server, model deployment tools, Spark UDFs
  • area/evaluation: MLflow model evaluation features, evaluation metrics, and evaluation workflows
  • area/gateway: MLflow AI Gateway client APIs, server, and third-party integrations
  • area/prompts: MLflow prompt engineering features, prompt templates, and prompt management
  • area/tracing: MLflow Tracing features, tracing APIs, and LLM tracing functionality
  • area/projects: MLproject format, project running backends
  • area/uiux: Front-end, user experience, plotting, JavaScript, JavaScript dev server
  • area/build: Build and test infrastructure for MLflow
  • area/docs: MLflow documentation pages

How should the PR be classified in the release notes? Choose one:

  • rn/none - No description will be included. The PR will be mentioned only by the PR number in the "Small Bugfixes and Documentation Updates" section
  • rn/breaking-change - The PR will be mentioned in the "Breaking Changes" section
  • rn/feature - A new user-facing feature worth mentioning in the release notes
  • rn/bug-fix - A user-facing bug fix worth mentioning in the release notes
  • rn/documentation - A user-facing documentation change worth mentioning in the release notes

Should this PR be included in the next patch release?

Yes should be selected for bug fixes, documentation updates, and other small changes. No should be selected for new features and larger changes. If you're unsure about the release classification of this PR, leave this unchecked to let the maintainers decide.

What is a minor/patch release?
  • Minor release: a release that increments the second part of the version number (e.g., 1.2.0 -> 1.3.0).
    Bug fixes, doc updates and new features usually go into minor releases.
  • Patch release: a release that increments the third part of the version number (e.g., 1.2.0 -> 1.2.1).
    Bug fixes and doc updates usually go into patch releases.
  • Yes (this PR will be cherry-picked and included in the next patch release)
  • No (this PR will be included in the next minor release)

Signed-off-by: Weichen Xu <weichen.xu@databricks.com>
Signed-off-by: Weichen Xu <weichen.xu@databricks.com>
Copilot AI review requested due to automatic review settings February 5, 2026 09:59
@github-actions
Copy link
Contributor

github-actions bot commented Feb 5, 2026

🛠 DevTools 🛠

Install mlflow from this PR

# mlflow
pip install git+https://github.com/mlflow/mlflow.git@refs/pull/20591/merge
# mlflow-skinny
pip install git+https://github.com/mlflow/mlflow.git@refs/pull/20591/merge#subdirectory=libs/skinny

For Databricks, use the following command:

%sh curl -LsSf https://raw.githubusercontent.com/mlflow/mlflow/HEAD/dev/install-skinny.sh | sh -s pull/20591/merge

@github-actions github-actions bot added area/docs Documentation issues rn/documentation Mention under Documentation Changes in Changelogs. labels Feb 5, 2026
![App basic information](/images/self-hosting/sso-okta-app-info.png)

3. Configure allowed callback URL for the Okta application, assuming the MLflow server is deployed at "http://127.0.0.1:8080", then the callback URL is "http://127.0.0.1:8080/callback"
3. Configure allowed callback URL for the Okta application, assuming the MLflow server is deployed at "http://localhost:8080", then the callback URL is "http://localhost:8080/callback"
Copy link
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For Google identity platform, http://127.0.0.1:8080/callback is not a valid callback URL. So I change it to use localhost

Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Did localhost work for all providers?

Copy link
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

yes.

Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates the SSO OIDC plugin documentation to add comprehensive configuration instructions for Google Identity Platform as an additional identity provider option alongside the existing Okta Auth0 documentation. The changes also standardize URLs from 127.0.0.1 to localhost throughout the documentation.

Changes:

  • Added new section with step-by-step Google Identity Platform configuration instructions, including OAuth credentials setup and a custom Python plugin for group detection
  • Reorganized existing Okta Auth0 content under a dedicated subsection header for better clarity
  • Updated deployment instructions to accommodate both Okta Auth0 and Google Identity Platform configurations with provider-specific environment variables

@github-actions
Copy link
Contributor

github-actions bot commented Feb 5, 2026

Documentation preview for 6c4a81a is available at:

Changed Pages (1)

More info
  • Ignore this comment if this PR does not change the documentation.
  • The preview is updated when a new commit is pushed to this PR.
  • This comment was created by this workflow run.
  • The documentation was built by this workflow run.

Signed-off-by: Weichen Xu <weichen.xu@databricks.com>
Signed-off-by: Weichen Xu <weichen.xu@databricks.com>
Signed-off-by: Weichen Xu <weichen.xu@databricks.com>
Signed-off-by: Weichen Xu <weichen.xu@databricks.com>
@TomeHirata TomeHirata self-assigned this Feb 6, 2026
Signed-off-by: Weichen Xu <weichen.xu@databricks.com>
Signed-off-by: Weichen Xu <weichen.xu@databricks.com>
@WeichenXu123 WeichenXu123 changed the title Update SSO oidc plugin doc: add google identity platform configuration guide Update SSO oidc plugin doc: add google identity platform / AWS cognito / Azure Entra ID configuration guide Feb 8, 2026
Signed-off-by: Weichen Xu <weichen.xu@databricks.com>
Signed-off-by: Weichen Xu <weichen.xu@databricks.com>
Signed-off-by: Weichen Xu <weichen.xu@databricks.com>
Copy link
Collaborator

@TomeHirata TomeHirata left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@WeichenXu123 WeichenXu123 added this pull request to the merge queue Feb 12, 2026
Merged via the queue into mlflow:master with commit 7dafb59 Feb 12, 2026
13 of 15 checks passed
@WeichenXu123 WeichenXu123 deleted the sso-doc-update branch February 12, 2026 03:48
daniellok-db pushed a commit to daniellok-db/mlflow that referenced this pull request Mar 5, 2026
…o / Azure Entra ID configuration guide (mlflow#20591)

Signed-off-by: Weichen Xu <weichen.xu@databricks.com>
daniellok-db pushed a commit that referenced this pull request Mar 5, 2026
…o / Azure Entra ID configuration guide (#20591)

Signed-off-by: Weichen Xu <weichen.xu@databricks.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/docs Documentation issues rn/documentation Mention under Documentation Changes in Changelogs.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants