Prompt
What’s the best way to add SSO to an existing app without forcing a migration?
Latest observation
Oct 7, 2026
OpenAI APIWeb search: off
The usual best way is to add SSO as an additional login path, not a replacement, then link existing accounts to identities from the IdP behind the scenes.
Recommended approach
-
Keep current auth working
- Don’t remove password/email login yet.
- Introduce SSO as an option alongside existing sign-in.
-
Use an external identity provider
- Support OIDC/OAuth2 if possible; use SAML only if you need enterprise compatibility.
- This lets you avoid building and maintaining your own SSO logic.
-
Add account linking
- When a user signs in with SSO, match them to an existing account by:
- verified email, or
- an explicit linking flow if email isn’t reliable.
- Store the IdP subject (
sub) / SAML NameID as the external identity reference.
- When a user signs in with SSO, match them to an existing account by:
-
Progressive migration
- Let users continue using password login until they choose to switch.
- Encourage linking with prompts like “Connect your organization account.”
- After link, you can optionally make SSO preferred for that user/org.
-
Support domain-based routing
- For enterprise orgs, route users with company email domains to SSO automatically.
- Still allow manual login fallback.
-
Be careful with edge cases
- Handle users with the same email across tenants/orgs.
- Require email verification before auto-linking.
- Decide what happens if the IdP email changes.
- If the IdP is unavailable, keep a fallback path.
Practical architecture
- Add an identity table:
user_idprovider(okta, azuread, google, etc.)provider_user_id/subtenant/org id- timestamps
- Authentication flow:
- User clicks “Sign in with SSO”
- Redirect to IdP
- Receive callback/assertion
- Find or link local user
- Create app session
Best rollout strategy
- Phase 1: add SSO, keep passwords
- Phase 2: enable optional account linking
- Phase 3: make SSO default for specific orgs/domains
- Phase 4: deprecate passwords only if/when business rules allow it
Key principle
Do not force a “big bang” migration.
Instead, make SSO additive, then gradually move users/orgs over once their accounts are linked and the flow is stable.
If you want, I can sketch a concrete migration plan for OIDC, SAML, or a specific stack like Auth0 / Okta / Azure AD / Keycloak.