Skip to content

Latest commit

 

History

History
163 lines (149 loc) · 67.3 KB

File metadata and controls

163 lines (149 loc) · 67.3 KB

Provider Compatibility

This matrix is a provider behavior map, not a production certification claim. provider-ready means the XID route and configuration surface exist; L4 still needs a real provider or IdP run without recording secrets, OTP values, SAMLResponse values, authorization codes, refresh tokens, cookies, or provider tokens.

Goal completion gate: local implementation can close with fake provider or fake SaaS L3. Missing real provider/IdP/SaaS L4 blocks only production-supported claims. Role 2, role 4 inbound, and role 5 provider-ready rows still need real external runs; role 3 downstream SaaS SSO and downstream SaaS SCIM target clients have local baseline evidence but still need real SaaS L4. Passing source-map tests proves matrix alignment, not production-supported completion.

Search date: 2026-06-08. Official sources checked: Auth0 Enterprise Connections, Auth0 Enterprise Identity Providers, Auth0 WS-Fed protocol, Auth0 Social Identity Providers, Auth0 SAML/OIDC outbound SSO and GitHub Enterprise Cloud guide, Clerk Enterprise SSO, Clerk Social Connections, Clerk OAuth SSO, Clerk Directory Sync SCIM, Zitadel identity brokering, Zitadel external identity provider and social login guides, Zitadel Okta OIDC/SAML and SCIM guides, Zitadel OpenLDAP guide, Microsoft Entra SAML/OIDC SSO, SSO options, app gallery, app integration, app provisioning and SCIM docs, Microsoft identity platform OIDC docs, Okta app integration and SCIM provisioning docs, PingOne SAML/OIDC application docs, PingFederate SAML/OIDC browser SSO docs, AD FS SAML/OIDC docs, Shibboleth SAML/OIDC plugin docs, Keycloak server admin docs, Slack custom SAML and SCIM docs, GitHub OAuth app and Enterprise SAML/SCIM docs, Atlassian SAML/SCIM docs, Salesforce SAML/OIDC/SCIM docs, Zoom SAML/OIDC/SCIM docs, Google OpenID Connect docs, and Apple Sign in with Apple docs.

Official source URLs:

  • Auth0 Enterprise Connections: https://auth0.com/docs/authenticate/enterprise-connections
  • Auth0 Enterprise Identity Providers: https://auth0.com/docs/authenticate/identity-providers/enterprise-identity-providers
  • Auth0 WS-Fed protocol: https://auth0.com/docs/authenticate/protocols/ws-fed-protocol
  • Auth0 Social Identity Providers: https://auth0.com/docs/authenticate/identity-providers/social-identity-providers
  • Auth0 Google social connection: https://auth0.com/docs/authenticate/identity-providers/social-identity-providers/google
  • Auth0 GitHub social connection: https://auth0.com/docs/authenticate/identity-providers/social-identity-providers/github
  • Auth0 custom OAuth2 social connection: https://auth0.com/docs/authenticate/identity-providers/social-identity-providers/oauth2
  • Auth0 Inbound SCIM: https://auth0.com/docs/authenticate/protocols/scim/configure-inbound-scim
  • Auth0 outbound SAML IdP for GitHub Enterprise Cloud: https://auth0.com/docs/authenticate/single-sign-on/outbound-single-sign-on/configure-auth0-saml-identity-provider/configure-saml2-web-app-addon-for-github-enterprise-cloud
  • Clerk Enterprise SSO: https://clerk.com/docs/guides/configure/auth-strategies/enterprise-connections/overview
  • Clerk Social Connections: https://clerk.com/docs/nextjs/guides/configure/auth-strategies/social-connections/overview
  • Clerk OAuth SSO: https://clerk.com/docs/guides/configure/auth-strategies/oauth/single-sign-on
  • Clerk Google social connection: https://clerk.com/docs/guides/configure/auth-strategies/social-connections/google
  • Clerk GitHub social connection: https://clerk.com/docs/guides/configure/auth-strategies/social-connections/github
  • Clerk Apple social connection: https://clerk.com/docs/guides/configure/auth-strategies/social-connections/apple
  • Clerk Directory Sync SCIM: https://clerk.com/docs/guides/configure/auth-strategies/enterprise-connections/directory-sync
  • Zitadel external identity providers: https://zitadel.com/docs/guides/integrate/identity-providers/introduction
  • Zitadel identity brokering: https://zitadel.com/docs/concepts/features/identity-brokering
  • Zitadel Google identity provider: https://zitadel.com/docs/guides/integrate/identity-providers/google
  • Zitadel Apple identity provider: https://zitadel.com/docs/guides/integrate/identity-providers/apple
  • Zitadel Okta OIDC: https://zitadel.com/docs/guides/integrate/identity-providers/okta-oidc
  • Zitadel Okta SAML: https://zitadel.com/docs/guides/integrate/identity-providers/okta_saml
  • Zitadel OpenLDAP identity provider: https://zitadel.com/docs/guides/integrate/identity-providers/openldap
  • Zitadel Okta SCIM: https://zitadel.com/docs/guides/integrate/scim-okta-guide
  • Microsoft Entra SSO options: https://learn.microsoft.com/en-us/entra/identity/enterprise-apps/what-is-single-sign-on
  • Microsoft Entra plan SSO deployment: https://learn.microsoft.com/en-us/entra/identity/enterprise-apps/plan-sso-deployment
  • Microsoft Entra SAML SSO: https://learn.microsoft.com/en-us/entra/identity/enterprise-apps/add-application-portal-setup-sso
  • Microsoft Entra OIDC SSO: https://learn.microsoft.com/en-us/entra/identity/enterprise-apps/add-application-portal-setup-oidc-sso
  • Microsoft Entra SCIM provisioning: https://learn.microsoft.com/en-us/entra/identity/app-provisioning/use-scim-to-provision-users-and-groups
  • Microsoft Entra app provisioning overview: https://learn.microsoft.com/en-us/entra/identity/app-provisioning/user-provisioning
  • Microsoft Entra application gallery: https://learn.microsoft.com/en-us/entra/identity/enterprise-apps/overview-application-gallery
  • Microsoft Entra app integration planning: https://learn.microsoft.com/en-us/entra/identity/enterprise-apps/plan-an-application-integration
  • Okta app integrations: https://developer.okta.com/docs/guides/create-an-app-integration/-/main/
  • Okta SCIM provisioning for app integrations: https://help.okta.com/oie/en-us/Content/Topics/Apps/Apps_App_Integration_Wizard_SCIM.htm
  • PingOne SAML application: https://docs.pingidentity.com/pingoneforenterprise/pingone_for_enterprise/p14e_add_update_saml_application.html
  • PingOne OIDC application: https://docs.pingidentity.com/pingoneforenterprise/pingone_for_enterprise/p14e_integrate_oidc_application.html
  • PingFederate OIDC RP support: https://docs.pingidentity.com/pingfederate/13.0/administrators_reference_guide/pf_oidc_relying_party_support.html
  • PingFederate browser SSO configuration: https://docs.pingidentity.com/pingfederate/13.0/administrators_reference_guide/help_idpconnectionconfigtasklet_idpbrowserssostate.html
  • AD FS OAuth and OpenID Connect: https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-adfsod/7fc51569-b46d-4aba-8ae6-bad19cb9951b
  • AD FS relying party trust: https://learn.microsoft.com/en-us/windows-server/identity/ad-fs/operations/create-a-relying-party-trust
  • Shibboleth OIDC OP plugin: https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/1376878976/OIDC+OP
  • Shibboleth OIDC RP plugin: https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/1376878976/OIDC%20OP
  • Keycloak server admin guide: https://www.keycloak.org/docs/latest/server_admin/
  • Slack custom SAML: https://slack.com/help/articles/205168057-Custom-SAML-single-sign-on
  • Slack SCIM: https://api.slack.com/scim
  • GitHub Enterprise Cloud SAML IdP connection: https://docs.github.com/en/enterprise-cloud@latest/organizations/managing-saml-single-sign-on-for-your-organization/connecting-your-identity-provider-to-your-organization
  • GitHub Enterprise Managed Users SAML SSO: https://docs.github.com/en/enterprise-cloud@latest/admin/managing-iam/configuring-authentication-for-enterprise-managed-users/configuring-saml-single-sign-on-for-enterprise-managed-users
  • GitHub Enterprise Cloud SCIM for Enterprise Managed Users: https://docs.github.com/en/enterprise-cloud@latest/admin/managing-iam/provisioning-user-accounts-with-scim/configuring-scim-provisioning-for-users
  • GitHub OAuth apps: https://docs.github.com/en/apps/oauth-apps/building-oauth-apps/authorizing-oauth-apps
  • Atlassian connect identity provider: https://support.atlassian.com/provisioning-users/docs/what-are-setup-options-for-provisioning-and-single-sign-on/
  • Atlassian SAML SSO: https://support.atlassian.com/security-and-access-policies/docs/configure-saml-single-sign-on-with-an-identity-provider/
  • Atlassian SCIM provisioning: https://support.atlassian.com/provisioning-users/docs/configure-user-provisioning-with-an-identity-provider/
  • Salesforce SAML Service Provider browser/manual verified: https://help.salesforce.com/s/articleView?id=xcloud.sso_saml.htm&type=5
  • Salesforce OIDC Authentication Provider: https://developer.salesforce.com/docs/platform/mobile-sdk/guide/sso-provider-openid-connect.html
  • Salesforce SCIM: https://help.salesforce.com/s/articleView?id=xcloud.identity_scim_overview.htm&language=en_US&type=5
  • Zoom SAML SSO: https://support.zoom.com/hc/en/article?id=zm_kb&sysparm_article=KB0065487
  • Zoom OIDC SSO: https://support.zoom.com/hc/en/article?id=zm_kb&sysparm_article=KB0083701
  • Zoom SCIM2: https://developers.zoom.us/docs/api/scim2/
  • Google OpenID Connect: https://developers.google.com/identity/openid-connect/openid-connect
  • Microsoft identity platform OIDC: https://learn.microsoft.com/en-us/entra/identity-platform/v2-protocols-oidc
  • Microsoft identity platform authorization code flow: https://learn.microsoft.com/en-us/entra/identity-platform/v2-oauth2-auth-code-flow
  • Apple Sign in with Apple REST API: https://developer.apple.com/documentation/signinwithapplerestapi
  • Apple Sign in with Apple web configuration: https://developer.apple.com/help/account/capabilities/configure-sign-in-with-apple-for-the-web/

Role rule: Microsoft Entra ID, Microsoft account, and Microsoft custom enterprise app are separate rows. GitHub Social OAuth and GitHub Enterprise SAML SSO are separate rows. Google Social OAuth and Google Workspace enterprise SSO/SCIM are separate rows. Slack, Atlassian, Salesforce, and Zoom are not Social OAuth providers here; they are downstream SaaS SPs or SCIM targets.

Official boundary notes:

  • Clerk Directory Sync is SCIM 2.0 generally available; XID still needs real IdP provisioning L4 before provider-ready rows become complete.
  • Auth0 Inbound SCIM supports SAML, OpenID Connect, Okta Workforce Identity, and Microsoft Azure AD / Entra ID enterprise connection types. It supports user create, get, put, patch, delete, search, deactivate, SCIM core user schema, Enterprise User extension, connection-specific bearer tokens, token rotation, and attribute mapping, but Auth0 documents that it does not support a /groups endpoint for full group objects and group memberships. Auth0 SCIM deactivation blocks the user, terminates Auth0 sessions, revokes refresh tokens, and can trigger OIDC Back-Channel Logout when configured. XID role 4 has local Users and Groups evidence, but still needs real IdP provisioning L4 before production claims.
  • Auth0 outbound SSO documents IdP-initiated marketplace integrations for services like Dropbox, Slack, and Zoom, plus custom SAML or OIDC implementations. This is role 3 evidence that downstream SaaS SSO is a distinct product surface from inbound enterprise connections.
  • Clerk Enterprise SSO supports SAML and OIDC, including Microsoft Azure AD, Google Workspace, Okta Workforce, generic SAML IdPs, and OIDC-compatible providers. Clerk EASIE OIDC is a multi-tenant IdP path for Google Workspace and Microsoft Entra ID and is not equivalent to XID downstream SaaS app catalog support.
  • Clerk Directory Sync is SCIM 2.0 Service Provider behavior: the IdP pushes create, update, delete, and disable events into Clerk, Clerk revokes active sessions on deprovisioning, SAML or OIDC enterprise connection setup is required, and SCIM emails must contain email for each user.
  • Okta app integrations support OIDC, SAML, SWA, WS-Fed, and SCIM, but Okta custom SCIM provisioning is not currently supported on OIDC app integrations. Keep Okta OIDC upstream login and Okta SCIM provisioning as separate evidence inputs.
  • Okta AIW SCIM provisioning requires first creating a SAML or SWA SSO integration that supports SCIM; authentication modes include Basic Auth, HTTP Header bearer token, and OAuth 2.0 Client Credentials or Authorization Code.
  • Microsoft Entra SCIM provisioning targets an application's SCIM endpoint, runs synchronization for assigned users and groups, performs Test Connection by querying a non-existent user and expecting HTTP 200 with an empty ListResponse, and later sync cycles run about every 40 minutes. This is role 4 only when Microsoft Entra provisions into XID.
  • Microsoft Entra SCIM gallery onboarding expects a SCIM 2.0 user and group endpoint, schema discovery, PATCH group membership updates, public SCIM documentation, and OAuth 2.0 client credentials for new gallery connectors. XID current local SCIM evidence does not replace a real Entra provisioning L4 run.
  • Zitadel SCIM from Okta requires an existing SAML app between Okta and ZITADEL, ZITADEL service-account authentication by PAT or client credentials, Org User Manager role, and SCIM connector base URL https://${ZITADEL_DOMAIN}/scim/v2/{orgId}. This is Okta-to-ZITADEL inbound SCIM Service Provider evidence, not outbound SaaS SCIM push evidence.
  • GitHub Enterprise Managed Users can use OIDC only on the Microsoft Entra ID partner path. XID exposes a github_emu Social OAuth preset with EMU issuer boundary checks (including https://token.actions.githubusercontent.com and Entra tenant issuers) and external_id claim mapping to users.external_id for org console configuration. This is upstream Social OAuth RP support only; generic downstream GitHub Enterprise OIDC IdP support for XID remains out of scope.
  • Google OpenID Connect covers Sign in with Google server flow with OAuth credentials, registered redirect URI, state, authorization code exchange, ID token, issuer, audience, and nonce. Keep Google Social OAuth separate from Google Workspace enterprise SSO and SCIM.
  • Auth0, Clerk, and Zitadel all document social or external identity provider login. This confirms role 5 as a separate competitor baseline from enterprise inbound SSO and downstream SaaS SSO.
  • Clerk OAuth SSO documents both directions: users can sign in to Clerk with external providers, and Clerk can act as OAuth 2.0/OIDC IdP for third-party clients. XID role 1 covers generic OAuth/OIDC clients, while role 3 remains planned for SaaS-specific Slack/GitHub/Microsoft app catalog support.
  • GitHub OAuth apps support OAuth 2.0 authorization code flow for browser apps, while GitHub Enterprise SAML/SCIM is a separate enterprise product path.
  • Microsoft identity platform OIDC and authorization code flow support Microsoft account login through app registration, while Microsoft Entra ID enterprise SSO and Microsoft custom enterprise app remain separate rows.
  • Apple Sign in with Apple requires web Services ID/private key setup and server-side identity token validation. XID Apple social OAuth is implemented locally with fake harness L3 and unit tests; real Apple credentials and callback L4 remain required before production-supported claims.
  • Auth0 Enterprise Identity Providers lists Active Directory/LDAP, ADFS, Google Workspace, OIDC, Okta, PingFederate, SAML, and Azure AD. Auth0 WS-Fed docs cover WS-Fed application endpoints and ADFS/WS-Fed identity provider setup. LDAP direct bind, WS-Federation, SWA password vaulting, and header-based SSO have local legacy baseline routes in XID with fake harness L3; real AD/LDAP gateway and AD FS WS-Fed L4 remain missing.
  • Okta app integrations include OIDC, SAML, SWA, WS-Fed, and SCIM. XID implements SWA/password vaulting and WS-Federation with fake harness L3 for inbound enterprise SSO.
  • Microsoft Entra SSO options include SAML 2.0, WS-Federation, OpenID Connect, password-based SSO, linked sign-on, Integrated Windows Authentication, and header-based SSO. XID implements SAML/OIDC federation plus legacy WS-Fed, SWA/password vaulting, and header-based SSO baseline; linked sign-on and native IWA/Kerberos remain out of scope.
  • Microsoft Entra app provisioning covers SCIM plus LDAP, SQL, REST, SOAP, flat-file, PowerShell, and custom ECMA connectors. XID role 4 is SCIM Service Provider with directory connector registry stubs for non-SCIM connectors.
  • Zitadel identity brokering documents OIDC, SAML2, and LDAP external IdPs. LDAP direct bind is implemented locally via HTTP gateway or fake LDAP harness.
  • Slack custom SAML confirms Slack is the SP: ACS URL https://yourdomain.slack.com/sso/saml, Entity ID https://slack.com, HTTP POST binding only, signed SAML Response, required NameID and User.Email, IdP-initiated and SP-initiated SSO, JIT, SCIM provisioning, and no Single Logout. XID Slack support is role 3 implemented for the local outbound SAML baseline, console preset wizard, and fake SaaS SP L3; real Slack admin L4 is still required before production-supported claims.
  • Slack SCIM is a downstream target API with SCIM 2.0 base path /scim/v2, Bearer OAuth token with admin scope, Business+ or Enterprise plan requirement, and Enterprise org token obtained by installing the SCIM app on the Enterprise organization. XID inbound SCIM Service Provider evidence cannot be reused as Slack SCIM push-to-SaaS support.
  • GitHub organization SAML SSO connects an external IdP to a GitHub Enterprise Cloud organization. Organization SCIM supported IdPs are Entra ID, Okta, and OneLogin; it cannot be used with an enterprise account or an organization with managed users. XID GitHub Enterprise Cloud support is implemented for the local outbound SAML baseline, console preset wizard, and fake SaaS L3; real GitHub Enterprise Cloud L4 is still required before production-supported claims.
  • GitHub Enterprise Managed Users SCIM is IdP-to-GitHub lifecycle management. Partner IdP paths include Entra ID OIDC/SAML, Okta SAML, and PingFederate SAML; non-partner provisioning can use GitHub REST API endpoints for SCIM, but REST API SCIM is not supported with enterprises enabled for OIDC. XID outbound SCIM client baseline now has fake SaaS SCIM target L3, but real GitHub Enterprise Managed Users setup and production L4 are still required before production-supported claims.
  • PingOne for Enterprise documents SAML applications with metadata, ACS URL, Entity ID, signing certificate, assertion encryption, and optional SLO, and OIDC applications with discovery URL, authorization endpoint, redirect URI validation, code/implicit/hybrid grant types, token endpoint, userinfo, and JWKS. XID role 2 is implemented for PingOne SAML/OIDC upstream presets, runbooks, and fake IdP L3; real PingOne config/callback L4 is still missing.
  • PingFederate documents SAML 2.0, WS-Federation, and OpenID Connect browser SSO configuration, plus OIDC RP support against upstream OPs. XID role 2 covers PingFederate SAML/OIDC implemented presets and fake IdP L3; WS-Federation has a separate local legacy baseline.
  • AD FS documents relying party trusts for SAML 2.0 WebSSO and WS-Federation Passive protocol, plus OAuth/OIDC endpoints and OpenID Connect Discovery/Core support. XID role 2 covers AD FS SAML/OIDC implemented presets and fake IdP L3; AD FS WS-Fed has a separate local legacy baseline.
  • Shibboleth documents native SAML IdP behavior and official OIDC OP/RP plugins. XID role 2 covers Shibboleth SAML/OIDC implemented presets and fake IdP L3 only; plugin-specific metadata and callback L4 are still missing.
  • Keycloak documents OIDC, OAuth 2.0, SAML, identity brokering for external OIDC/SAML IdPs, Social Login, LDAP/AD user federation, and Kerberos bridge. XID role 2 covers Keycloak SAML/OIDC implemented presets and fake IdP L3. Keycloak LDAP/AD user federation has a separate XID LDAP direct bind baseline; native Kerberos bridge remains documented-only.
  • Atlassian Cloud uses Atlassian Guard identity provider setup for SAML single sign-on and SCIM provisioning. Atlassian is implemented locally through outbound SAML console presets, runbooks, and fake SaaS L3; real Atlassian admin L4 is still required before production-supported claims.
  • Salesforce Help was browser/manual verified when direct fetch returned only Loading. Official docs cover Salesforce orgs or Experience Cloud sites as SAML Service Providers, Salesforce as a relying party for third-party OpenID providers, and Salesforce user identity management with SCIM. Salesforce SCIM supports REST API create, read, update, and disable user operations, deactivate/reactivate behavior, and group member management. Salesforce is implemented locally through outbound SAML/OIDC presets, runbooks, and fake SaaS L3; real Salesforce admin L4 is still required before production-supported claims.
  • Zoom official docs state Zoom acts as the Service Provider for SAML SSO, supports OIDC SSO configuration, and exposes SCIM2 user/group provisioning APIs. Zoom is implemented locally through outbound SAML/OIDC presets, runbooks, and fake SaaS L3; real Zoom admin L4 is still required before production-supported claims.

Enterprise Legacy Protocol Boundary

These protocols appear in the searched enterprise SSO ecosystem. XID now has local baseline routes and tests for several legacy upstream methods; production-supported claims still require real external L4.

Capability Competitor/source signal Current XID boundary
WS-Fed / WS-Federation Auth0 WS-Fed protocol, Okta app integrations, Microsoft Entra SSO options Implemented locally: /sso/wsfed/:connectionId/login and callback wresult parsing with fake WS-Fed harness L3. Real AD FS/Entra signed wresult L4 missing.
LDAP direct bind as external IdP Auth0 Enterprise Identity Providers, Zitadel OpenLDAP identity provider Implemented locally: POST /sso/ldap/:connectionId/login via HTTP LDAP gateway or fake LDAP harness L3. Native LDAP sockets are not used in Workers.
SWA / password vaulting Okta app integrations, Microsoft Entra password-based SSO Implemented locally: POST /sso/swa/:connectionId/authenticate and /vault with hashed or envelope-encrypted credentials and fake SWA harness L3.
Header-based SSO Microsoft Entra header-based SSO, trusted reverse proxy pattern Implemented locally: POST /sso/header/:connectionId/authenticate with trusted headers and optional proxy secret. Real Application Proxy L4 missing.
Directory connector framework Microsoft Entra app provisioning overview Implemented locally: connector registry and validate routes; LDAP/header connectors implemented, SQL/REST/SOAP/PowerShell/ECMA remain stub.
Kerberos / IWA deployment pattern Microsoft Entra plan SSO deployment, Keycloak Kerberos bridge Documented only in docs/design/04-enterprise-sso.md. XID does not terminate Kerberos/SPNEGO in Workers.
Linked sign-on Microsoft Entra linked sign-on Not current target. XID does not publish link-only app launcher entries as SSO support.
LDAP/SQL/REST/SOAP/PowerShell provisioning connectors Microsoft Entra app provisioning overview Partial. XID implements SCIM Service Provider and connector registry stubs; non-SCIM connector execution is not production-supported.

Competitor Baseline

Platform Confirmed official capability XID alignment impact
Auth0 Enterprise Connections authenticate users against external IdPs such as Azure AD, Google Workspace, PingFederate, OIDC, and SAML. Enterprise Identity Providers also list Active Directory/LDAP and ADFS, and Auth0 WS-Fed protocol docs cover WS-Fed app and IdP flows. Social Identity Providers cover Google, GitHub, and generic OAuth2 social connections. Auth0 Inbound SCIM supports B2B SaaS provisioning for SAML, OpenID Connect, Okta Workforce Identity, and Microsoft Azure AD / Entra ID connections. Auth0 also documents outbound SAML/OIDC SSO integrations and outbound SAML IdP setup for GitHub Enterprise Cloud through the SAML2 Web App addon. XID has inbound SAML/OIDC, legacy LDAP/WS-Fed/SWA/header baseline, Social OAuth, SCIM, and generic OIDC/OAuth IdP rows, but no SaaS-specific outbound SAML/OIDC app catalog product surface. LDAP direct bind, WS-Federation, and SWA/password vaulting are implemented locally with fake harness L3. Auth0 outbound SAML IdP is the direct gap for role 3. Real AD/LDAP gateway and AD FS WS-Fed L4 are still missing.
Clerk Enterprise SSO supports SAML and OIDC for IdPs such as Microsoft Azure AD, Google Workspace, Okta Workforce, and generic compatible providers. Social Connections OAuth covers Google, GitHub, Apple, Microsoft-style providers, and production custom credentials. OAuth SSO also documents Clerk as OAuth 2.0/OIDC IdP for third-party clients. Directory Sync is SCIM 2.0 generally available and includes user, group, custom attribute, and role mapping behavior. XID must keep Social OAuth, generic customer-app OAuth/OIDC IdP, enterprise SSO, SaaS-specific outbound SSO, and SCIM as separate evidence lines. XID role 1 has generic OAuth/OIDC IdP evidence, and role 3 already has outbound SAML IdP baseline, but real SaaS L4 and SaaS-specific presets are still missing.
Zitadel Zitadel can connect external identity providers for social login and enterprise SSO, including Google, Apple, Okta OIDC, Okta SAML, and LDAP external IdPs, at instance or organization scope. Zitadel SCIM provisioning from Okta uses a SCIM v2.0 service provider endpoint and requires Okta admin setup plus service-account authentication. XID inbound OIDC RP, inbound SAML SP, LDAP direct bind baseline, Social OAuth RP, and SCIM Service Provider rows match this role class but still need real provider and Okta/Zitadel-style L4 runs before production claims. LDAP direct bind is current XID role 2 local baseline support.
Provider Protocols Support Evidence Code Tests Provider behavior to cover Current XID boundary Gap
Okta SAML, OIDC upstream, SCIM implemented L1/L2/L3 apps/server/worker/sso/saml.ts, apps/server/worker/sso/oidc-rp.ts, apps/server/worker/scim/users.ts, apps/server/worker/scim/groups.ts, apps/server/worker/scim/shared.ts, apps/server/worker/sso/provider-presets.ts, apps/server/worker/test-harness/fake-idp.ts, apps/console/src/routes/org/OrgSso.tsx apps/server/worker/sso/__tests__/saml-acs.test.ts, apps/server/worker/sso/__tests__/oidc-rp.test.ts, apps/server/worker/scim/__tests__/scim.test.ts, apps/server/tests/smoke/l3-inbound-saml.test.mjs, apps/server/worker/sso/__tests__/provider-presets.test.ts SAML POST ACS, signed response or assertion, NameID email or persistent, OIDC discovery, and SCIM Users/Groups. Okta custom SCIM provisioning is not currently supported on OIDC app integrations, so OIDC login and SCIM provisioning must be tested as separate inputs. SAML ACS, OIDC RP, JIT, SCIM core endpoints, enterprise User schema, simple filters, projection, PATCH, and invalidFilter guard exist Real Okta IdP metadata/config, SAML or OIDC callback, separate SCIM app config, and L4 evidence missing
Microsoft Entra ID SAML, OIDC upstream, SCIM implemented L1/L2/L3 apps/server/worker/sso/saml.ts, apps/server/worker/sso/oidc-rp.ts, apps/server/worker/scim/users.ts, apps/server/worker/scim/groups.ts, apps/server/worker/scim/shared.ts, apps/server/worker/sso/provider-presets.ts, apps/server/worker/test-harness/fake-idp.ts, apps/console/src/routes/org/OrgSso.tsx apps/server/worker/sso/__tests__/saml-acs.test.ts, apps/server/worker/sso/__tests__/oidc-rp.test.ts, apps/server/worker/scim/__tests__/scim.test.ts, apps/server/tests/smoke/l3-inbound-saml.test.mjs, apps/server/worker/sso/__tests__/provider-presets.test.ts Entra SAML claims, OIDC discovery, group and role mapping, SCIM enterprise extension, attributes projection, and active deprovisioning SAML/OIDC connection config and SCIM enterprise schema metadata, projection, PATCH, active deprovisioning, and required ETag/If-Match optimistic concurrency exist Real Entra ID provider config, SCIM app config, callback, and L4 evidence missing
Google Workspace OIDC upstream, SAML, SCIM implemented L1/L2/L3 apps/server/worker/sso/saml.ts, apps/server/worker/sso/oidc-rp.ts, apps/server/worker/scim/users.ts, apps/server/worker/scim/groups.ts, apps/server/worker/sso/provider-presets.ts, apps/server/worker/test-harness/fake-idp.ts, apps/console/src/routes/org/OrgSso.tsx apps/server/worker/sso/__tests__/saml-acs.test.ts, apps/server/worker/sso/__tests__/oidc-rp.test.ts, apps/server/worker/scim/__tests__/scim.test.ts, apps/server/tests/smoke/l3-inbound-saml.test.mjs, apps/server/worker/sso/__tests__/provider-presets.test.ts Google OIDC profile/email, SAML ACS, SCIM Users and Groups OIDC RP and SAML provider-ready routes exist; SCIM users/groups, simple filters, projection, and PATCH exist Real Google Workspace provider config, callback, and L4 evidence missing
OneLogin SAML, SCIM implemented L1/L2/L3 apps/server/worker/sso/saml.ts, apps/server/worker/scim/groups.ts, apps/server/worker/scim/users.ts, apps/server/worker/scim/shared.ts, apps/server/worker/sso/provider-presets.ts, apps/server/worker/test-harness/fake-idp.ts, apps/console/src/routes/org/OrgSso.tsx apps/server/worker/sso/__tests__/saml-acs.test.ts, apps/server/worker/scim/__tests__/scim.test.ts, apps/server/tests/smoke/l3-inbound-saml.test.mjs, apps/server/worker/sso/__tests__/provider-presets.test.ts Group PATCH can arrive before User creation; unknown group member references must resolve later Pending group member repair exists and is directory-scoped; Group PATCH remains idempotent for unknown members Real OneLogin provider config, SAML callback, SCIM app config, and L4 evidence missing
JumpCloud SAML, SCIM implemented L1/L2/L3 apps/server/worker/sso/saml.ts, apps/server/worker/scim/users.ts, apps/server/worker/scim/groups.ts, apps/server/worker/scim/shared.ts, apps/server/worker/sso/provider-presets.ts, apps/server/worker/test-harness/fake-idp.ts, apps/console/src/routes/org/OrgSso.tsx apps/server/worker/sso/__tests__/saml-acs.test.ts, apps/server/worker/scim/__tests__/scim.test.ts, apps/server/tests/smoke/l3-inbound-saml.test.mjs, apps/server/worker/sso/__tests__/provider-presets.test.ts Attribute names differ from Okta; SAML profile mapping and SCIM group membership mapping need provider fixture coverage Generic SAML attribute mapping and SCIM users/groups, projection, and PATCH exist Real JumpCloud SAML metadata/config, callback, SCIM app config, provider-specific fixtures, and L4 evidence missing
PingOne SAML, OIDC upstream implemented L1/L2/L3 apps/server/worker/sso/saml.ts, apps/server/worker/sso/oidc-rp.ts, apps/server/worker/sso/jit.ts, apps/server/worker/sso/provider-presets.ts, apps/server/worker/test-harness/fake-idp.ts, apps/console/src/routes/org/OrgSso.tsx apps/server/worker/sso/__tests__/saml-acs.test.ts, apps/server/worker/sso/__tests__/oidc-rp.test.ts, apps/server/worker/sso/__tests__/jit.test.ts, apps/server/tests/smoke/l3-inbound-saml.test.mjs, apps/server/worker/sso/__tests__/provider-presets.test.ts PingOne SAML apps expose metadata, ACS URL, Entity ID, signing certificate, assertion encryption, and optional SLO; OIDC apps expose discovery URL, authorization endpoint, redirect URI validation, code/implicit/hybrid flows, token endpoint, userinfo, and JWKS Generic SAML ACS, OIDC RP discovery/callback, and JIT paths exist; WS-Fed has separate local legacy baseline Real PingOne SAML/OIDC app metadata/config, callback, provider-specific fixture, and L4 evidence missing
PingFederate SAML, OIDC upstream implemented L1/L2/L3 apps/server/worker/sso/saml.ts, apps/server/worker/sso/oidc-rp.ts, apps/server/worker/sso/jit.ts, apps/server/worker/sso/provider-presets.ts, apps/server/worker/test-harness/fake-idp.ts, apps/console/src/routes/org/OrgSso.tsx apps/server/worker/sso/__tests__/saml-acs.test.ts, apps/server/worker/sso/__tests__/oidc-rp.test.ts, apps/server/worker/sso/__tests__/jit.test.ts, apps/server/tests/smoke/l3-inbound-saml.test.mjs, apps/server/worker/sso/__tests__/provider-presets.test.ts PingFederate supports browser SSO with SAML 2.0, WS-Federation, and OIDC, and OIDC RP connections with discovery, token endpoint, userinfo, JWKS, PKCE, PAR, JARM, and request object options Generic SAML ACS, OIDC RP discovery/callback, and JIT paths exist; WS-Federation has separate local legacy baseline Real PingFederate SAML/OIDC app metadata/config, callback, provider-specific fixture, and L4 evidence missing
AD FS SAML, OIDC upstream implemented L1/L2/L3 apps/server/worker/sso/saml.ts, apps/server/worker/sso/oidc-rp.ts, apps/server/worker/sso/jit.ts, apps/server/worker/sso/provider-presets.ts, apps/server/worker/test-harness/fake-idp.ts, apps/console/src/routes/org/OrgSso.tsx apps/server/worker/sso/__tests__/saml-acs.test.ts, apps/server/worker/sso/__tests__/oidc-rp.test.ts, apps/server/worker/sso/__tests__/jit.test.ts, apps/server/tests/smoke/l3-inbound-saml.test.mjs, apps/server/worker/sso/__tests__/provider-presets.test.ts AD FS relying party trusts support SAML 2.0 WebSSO and WS-Federation Passive protocol, and AD FS implements OAuth/OIDC discovery, authorize, token, userinfo, logout, and keys endpoints Generic SAML ACS, OIDC RP discovery/callback, and JIT paths exist; AD FS WS-Fed has separate local legacy baseline Real AD FS SAML/OIDC metadata/config, callback, provider-specific fixture, and L4 evidence missing
Shibboleth SAML, OIDC upstream implemented L1/L2/L3 apps/server/worker/sso/saml.ts, apps/server/worker/sso/oidc-rp.ts, apps/server/worker/sso/jit.ts, apps/server/worker/sso/provider-presets.ts, apps/server/worker/test-harness/fake-idp.ts, apps/console/src/routes/org/OrgSso.tsx apps/server/worker/sso/__tests__/saml-acs.test.ts, apps/server/worker/sso/__tests__/oidc-rp.test.ts, apps/server/worker/sso/__tests__/jit.test.ts, apps/server/tests/smoke/l3-inbound-saml.test.mjs, apps/server/worker/sso/__tests__/provider-presets.test.ts Shibboleth IdP has native SAML support and official OIDC OP/RP plugins covering OIDC Core, Discovery, Dynamic Client Registration, logout profiles, introspection, JAR, PAR, issuer identification, and DPoP Generic SAML ACS, OIDC RP discovery/callback, and JIT paths exist; Shibboleth plugin-specific metadata behavior is not proven Real Shibboleth SAML/OIDC metadata/config, callback, plugin-specific fixture, and L4 evidence missing
Keycloak SAML, OIDC upstream implemented L1/L2/L3 apps/server/worker/sso/saml.ts, apps/server/worker/sso/oidc-rp.ts, apps/server/worker/sso/jit.ts, apps/server/worker/sso/provider-presets.ts, apps/server/worker/test-harness/fake-idp.ts, apps/console/src/routes/org/OrgSso.tsx apps/server/worker/sso/__tests__/saml-acs.test.ts, apps/server/worker/sso/__tests__/oidc-rp.test.ts, apps/server/worker/sso/__tests__/jit.test.ts, apps/server/tests/smoke/l3-inbound-saml.test.mjs, apps/server/worker/sso/__tests__/provider-presets.test.ts Keycloak supports OIDC, OAuth 2.0, SAML, identity brokering with external OIDC/SAML IdPs, Social Login, LDAP/AD user federation, and Kerberos bridge Generic SAML ACS, OIDC RP discovery/callback, and JIT paths exist; LDAP direct bind has separate local legacy baseline; native Kerberos bridge remains documented-only Real Keycloak SAML/OIDC metadata/config, callback, provider-specific fixture, and L4 evidence missing
GitHub Social OAuth implemented L1/L2/L3 apps/server/worker/auth/social.ts, apps/server/worker/auth/social-providers.ts, apps/console/src/routes/org/OrgSocialProviders.tsx, apps/server/worker/test-harness/fake-social.ts apps/server/worker/auth/__tests__/social.test.ts, apps/server/tests/smoke/l3-social-oauth.test.mjs OAuth authorization and callback with profile and email lookup Social OAuth code exists outside this protocol matrix; current production evidence must come from current package scripts and docs/protocols/source-map.md Real GitHub provider client secret, callback, and L4 evidence missing
Google Social OAuth/OIDC implemented L1/L2/L3 apps/server/worker/auth/social.ts, apps/server/worker/auth/social-providers.ts, apps/console/src/routes/org/OrgSocialProviders.tsx, apps/server/worker/test-harness/fake-social.ts apps/server/worker/auth/__tests__/social.test.ts, apps/server/worker/auth/__tests__/social-providers.test.ts, apps/server/tests/smoke/l3-social-oauth.test.mjs Google OIDC server flow, state, authorization code exchange, ID token, issuer, audience, nonce, email, and profile claims Google preset exists in the social provider console; shared OIDC provider resolver verifies id_token issuer, audience, signature, and nonce, then maps profile/email claims Real Google OAuth client secret/config, callback, and L4 evidence missing
GitHub Enterprise Cloud Downstream SAML SP, SCIM target implemented L1/L2/L3 apps/server/worker/sso/outbound-saml.ts, packages/saml/src/idp.ts, apps/server/worker/scim/outbound.ts, packages/db/src/schema/directory.ts, apps/server/worker/sso/provider-presets.ts, apps/console/src/routes/org/OrgOutboundSso.tsx apps/server/tests/smoke/l3-protocol-client.test.mjs, apps/server/worker/sso/__tests__/provider-presets.test.ts GitHub organization SAML SSO connects an external IdP to a GitHub Enterprise Cloud organization; organization SCIM supported IdPs are Entra ID, Okta, and OneLogin; Enterprise Managed Users SCIM is IdP-to-GitHub lifecycle management; Enterprise Managed Users OIDC is an Entra ID partner path, not generic downstream OIDC support for XID Generic outbound SAML and outbound SCIM baselines exist with fake SaaS L3, and the GitHub Enterprise UI preset exists locally; GitHub Enterprise metadata, real config, admin L4, callback evidence, and production evidence are missing Keep GitHub Social OAuth separate; real GitHub config, callback, and L4 evidence are missing before GitHub Enterprise production support
Slack Downstream SAML SP, SCIM target implemented L1/L2/L3 apps/server/worker/sso/outbound-saml.ts, packages/saml/src/idp.ts, apps/server/worker/scim/outbound.ts, packages/db/src/schema/directory.ts, apps/server/worker/sso/provider-presets.ts, apps/console/src/routes/org/OrgOutboundSso.tsx apps/server/tests/smoke/l3-protocol-client.test.mjs, apps/server/worker/sso/__tests__/provider-presets.test.ts Slack custom SAML supports IdP-initiated and SP-initiated SSO, JIT, SCIM provisioning, ACS URL https://yourdomain.slack.com/sso/saml, Entity ID https://slack.com, HTTP POST binding only, signed SAML Response, required NameID and User.Email, and no Single Logout; Slack SCIM uses /scim/v2 with a Bearer OAuth token containing admin scope Generic outbound SAML and outbound SCIM baselines exist with fake SaaS L3, and the Slack UI preset exists locally; Enterprise org SCIM install flow, real Slack admin L4, and production evidence are missing real Slack config, callback, admin permission, and L4 evidence are missing before Slack production support
Microsoft custom enterprise app Downstream SAML/OIDC SP implemented L1/L2/L3 apps/server/worker/sso/outbound-saml.ts, packages/saml/src/idp.ts, apps/server/worker/oidc/authorize.ts, apps/server/worker/oidc/token.ts, apps/server/worker/sso/provider-presets.ts, apps/console/src/routes/org/OrgOutboundSso.tsx apps/server/worker/oidc/__tests__/authorize.test.ts, apps/server/worker/oidc/__tests__/token.test.ts, apps/server/tests/smoke/l3-protocol-client.test.mjs, apps/server/worker/sso/__tests__/provider-presets.test.ts Microsoft Entra custom enterprise apps can be configured for SAML SSO or OIDC SSO, with Reply URL, Entity ID, Sign on URL, client ID, issuer, redirect URI, and claim mapping depending on protocol Generic outbound SAML and OIDC baselines, the Microsoft custom-app UI preset, and the assignment gate exist locally; claim mapping, real Entra custom-app L4, and production evidence are missing real Microsoft custom app config, callback, admin permission, and L4 evidence are missing before production support
Atlassian Downstream SAML SP, SCIM target implemented L1/L2/L3 apps/server/worker/sso/outbound-saml.ts, packages/saml/src/idp.ts, apps/server/worker/scim/outbound.ts, packages/db/src/schema/directory.ts, apps/server/worker/sso/provider-presets.ts, apps/console/src/routes/org/OrgOutboundSso.tsx apps/server/tests/smoke/l3-protocol-client.test.mjs, apps/server/worker/sso/__tests__/provider-presets.test.ts Atlassian Guard identity provider setup supports SAML single sign-on, JIT provisioning, and SCIM user provisioning for Atlassian Cloud accounts and groups Generic outbound SAML and outbound SCIM baselines exist with fake SaaS L3, and the Atlassian Guard UI preset exists locally; real Atlassian admin L4 and production evidence are missing real Atlassian config, callback, admin permission, production support, and L4 evidence are missing before Atlassian production support
Salesforce Downstream SAML/OIDC SP, SCIM target implemented L1/L2/L3 apps/server/worker/sso/outbound-saml.ts, packages/saml/src/idp.ts, apps/server/worker/oidc/authorize.ts, apps/server/worker/oidc/token.ts, apps/server/worker/scim/outbound.ts, packages/db/src/schema/directory.ts, apps/server/worker/sso/provider-presets.ts, apps/console/src/routes/org/OrgOutboundSso.tsx packages/saml/src/__tests__/verify.test.ts, apps/server/worker/oidc/__tests__/authorize.test.ts, apps/server/tests/smoke/l3-protocol-client.test.mjs, apps/server/worker/sso/__tests__/provider-presets.test.ts Browser/manual verified Salesforce Help confirms Salesforce orgs or Experience Cloud sites act as SAML Service Providers for external IdPs; Salesforce developer docs confirm Salesforce as a relying party for third-party OpenID providers; Salesforce SCIM docs confirm REST API create/read/update/disable user operations, deactivate/reactivate behavior, and group member management Generic outbound SAML, OIDC, and outbound SCIM baselines and the Salesforce UI preset exist locally; real Salesforce admin L4, callback evidence, and production evidence are missing real Salesforce config, callback, admin permission, and L4 evidence are missing before Salesforce production support
Zoom Downstream SAML/OIDC SP, SCIM target implemented L1/L2/L3 apps/server/worker/sso/outbound-saml.ts, packages/saml/src/idp.ts, apps/server/worker/oidc/authorize.ts, apps/server/worker/oidc/token.ts, apps/server/worker/scim/outbound.ts, packages/db/src/schema/directory.ts, apps/server/worker/sso/provider-presets.ts, apps/console/src/routes/org/OrgOutboundSso.tsx packages/saml/src/__tests__/verify.test.ts, apps/server/worker/oidc/__tests__/authorize.test.ts, apps/server/tests/smoke/l3-protocol-client.test.mjs, apps/server/worker/sso/__tests__/provider-presets.test.ts Zoom acts as the Service Provider for SAML SSO, supports OIDC SSO configuration, and exposes SCIM2 user/group provisioning APIs Generic outbound SAML, OIDC, and outbound SCIM baselines and the Zoom UI preset exist locally; approved vanity URL, real Zoom admin L4, callback evidence, and production evidence are missing real Zoom config, callback, admin permission, approved vanity URL, and L4 evidence are missing before Zoom production support
Apple Social OAuth/OIDC implemented L1/L2/L3 apps/server/worker/auth/social.ts, apps/server/worker/auth/social-providers.ts, apps/console/src/routes/org/OrgSocialProviders.tsx, apps/server/worker/test-harness/fake-social.ts apps/server/worker/auth/__tests__/social.test.ts, apps/server/worker/auth/__tests__/social-providers.test.ts, apps/server/tests/smoke/l3-social-oauth.test.mjs OIDC style identity token, private relay email, form_post callback, nonce verification Apple authorize sets response_mode=form_post; callback accepts POST form body; shared OIDC provider resolver verifies id_token issuer, audience, signature, and nonce, then preserves private relay email claims Real Apple provider client secret, callback, and L4 evidence missing
Microsoft account Social OAuth/OIDC implemented L1/L2/L3 apps/server/worker/auth/social.ts, apps/server/worker/auth/social-providers.ts, apps/console/src/routes/org/OrgSocialProviders.tsx, apps/server/worker/test-harness/fake-social.ts apps/server/worker/auth/__tests__/social.test.ts, apps/server/worker/auth/__tests__/social-providers.test.ts, apps/server/tests/smoke/l3-social-oauth.test.mjs OIDC profile/email, callback verification, nonce verification Microsoft account can be configured through the social provider surface; shared OIDC provider resolver verifies id_token issuer, audience, signature, and nonce, then maps profile/email claims Real Microsoft account provider client secret, callback, and L4 evidence missing
Twilio SMS OTP, WhatsApp OTP implemented L1/L2/L3 apps/server/worker/auth/delivery-channels.ts, apps/server/worker/queues/sms.ts, apps/server/worker/queues/whatsapp.ts, apps/server/worker/v1/organizations.ts, apps/console/src/routes/org/OrgDeliveryChannels.tsx, apps/server/worker/test-harness/test-otp.ts apps/server/worker/queues/__tests__/sms.test.ts, apps/server/worker/queues/__tests__/whatsapp.test.ts, apps/server/worker/v1/__tests__/isolation.test.ts, apps/console/src/routes/org/OrgDeliveryChannels.test.tsx, apps/server/tests/smoke/l3-delivery-otp.test.mjs Secret refs, sender readiness, OTP send, and delivery audit without token leakage Delivery channel UI/API, readiness gate, SMS queue, and WhatsApp queue cover Twilio form-encoded sends and redacted notification audit Real Twilio account secret, sender config, SMS or WhatsApp OTP delivery, and L4 evidence missing
Meta WhatsApp WhatsApp OTP implemented L1/L2/L3 apps/server/worker/auth/delivery-channels.ts, apps/server/worker/queues/whatsapp.ts, apps/server/worker/v1/organizations.ts, apps/console/src/routes/org/OrgDeliveryChannels.tsx, apps/server/worker/test-harness/test-otp.ts apps/server/worker/queues/__tests__/whatsapp.test.ts, apps/server/worker/v1/__tests__/isolation.test.ts, apps/console/src/routes/org/OrgDeliveryChannels.test.tsx, apps/server/tests/smoke/l3-delivery-otp.test.mjs Meta phone number ID, access token secret ref, OTP send, and delivery audit without token leakage Delivery channel UI/API, readiness gate, and WhatsApp queue cover Meta Cloud API JSON send with Bearer auth and redacted notification audit Real Meta access token secret, phone number config, WhatsApp OTP delivery, and L4 evidence missing
Vonage SMS OTP implemented L1/L2/L3 apps/server/worker/auth/delivery-channels.ts, apps/server/worker/queues/sms.ts, apps/server/worker/v1/organizations.ts, apps/console/src/routes/org/OrgDeliveryChannels.tsx, apps/server/worker/test-harness/test-otp.ts apps/server/worker/queues/__tests__/sms.test.ts, apps/server/worker/v1/__tests__/isolation.test.ts, apps/console/src/routes/org/OrgDeliveryChannels.test.tsx, apps/server/tests/smoke/l3-delivery-otp.test.mjs API key and secret, sender, OTP delivery and audit Delivery channel UI/API, readiness gate, and SMS queue cover Vonage JSON send and redacted notification audit Real Vonage API secret, sender config, SMS OTP delivery, and L4 evidence missing
Infobip SMS OTP implemented L1/L2/L3 apps/server/worker/auth/delivery-channels.ts, apps/server/worker/queues/sms.ts, apps/server/worker/v1/organizations.ts, apps/console/src/routes/org/OrgDeliveryChannels.tsx, apps/server/worker/test-harness/test-otp.ts apps/server/worker/queues/__tests__/sms.test.ts, apps/server/worker/v1/__tests__/isolation.test.ts, apps/console/src/routes/org/OrgDeliveryChannels.test.tsx, apps/server/tests/smoke/l3-delivery-otp.test.mjs API key, base URL, sender, OTP delivery and audit Delivery channel UI/API, readiness gate, and SMS queue cover Infobip JSON send and redacted notification audit Real Infobip API secret, base URL config, SMS OTP delivery, and L4 evidence missing
MessageBird SMS OTP implemented L1/L2/L3 apps/server/worker/auth/delivery-channels.ts, apps/server/worker/queues/sms.ts, apps/server/worker/v1/organizations.ts, apps/console/src/routes/org/OrgDeliveryChannels.tsx, apps/server/worker/test-harness/test-otp.ts apps/server/worker/queues/__tests__/sms.test.ts, apps/server/worker/v1/__tests__/isolation.test.ts, apps/console/src/routes/org/OrgDeliveryChannels.test.tsx, apps/server/tests/smoke/l3-delivery-otp.test.mjs Access key, originator, OTP delivery and audit Delivery channel UI/API, readiness gate, and SMS queue cover MessageBird form-encoded send and redacted notification audit Real MessageBird access key secret, originator config, SMS OTP delivery, and L4 evidence missing