Administer
Configure public addresses and organisation sign in
Map frontend and API origins, register OIDC callbacks, and allow intended browser integrations.
Before you start
Prepare DNS, trusted HTTPS certificates, and gateway routes for every browser address. An origin is a scheme, hostname, and optional port without a path.
Configure the addresses
- As System Owner, open System Configuration, then Public addresses and CORS.
- Add each frontend origin and its browser facing API origin. Multiple frontend addresses may map to the same installation.
- Open Authentication connections and edit each OpenID Connect profile.
- Add the matching frontend and callback mappings. Register each exact callback with the identity provider as a confidential Web application redirect URI.
- Under Additional browser API access (CORS), add only approved integration origins. Leave session cookies off for bearer token clients.
- Save and reload each frontend.
Check the result
Test sign in from every public address and confirm the returned browser stays on its intended frontend. A private cluster address must not become the public sign in destination.
The API still checks authentication, tenant access, and exact resource actions. Allowing an origin does not grant Product permission.
If sign in returns to the wrong place
Compare the browser origin, mapped API origin, proxy route, and registered callback exactly. Check HTTPS trust on the browser and servers. Do not use a wildcard to hide a mapping error.
Next step
Was this page helpful?
Your answer helps us improve the documentation.
Do not include personal information, customer information, passwords, or keys.