Single Sign-On
OpenBoxes Lift includes built-in single sign-on (SSO) powered by Keycloak. Every Lift account benefits from SSO --- you sign in once and get access to both the Lift portal and your OpenBoxes instance without re-entering credentials.
How SSO Works
When you sign in at app.openboxes.cloud, Keycloak (hosted at auth.openboxes.cloud) handles the authentication. Here is the flow:
- You enter your email and password on the Lift login page
- Keycloak verifies your credentials and creates a session
- You are signed into the Lift portal
- When you click Launch OpenBoxes, the portal uses your existing session to authenticate you with OpenBoxes automatically
- OpenBoxes opens in a new tab --- no second login required
This means your team only needs to remember one set of credentials for everything on the Lift platform.
Session Management
Session Duration
Your SSO session stays active as long as you are using the platform. Sessions expire after a period of inactivity:
| Setting | Duration |
|---|---|
| Session timeout (idle) | 14 days |
| Session maximum | 30 days |
When your session expires, you are redirected to the login page. Any unsaved work in OpenBoxes is preserved --- you can pick up where you left off after signing back in.
Signing Out
Clicking Sign Out in the portal terminates your SSO session across all Lift services. You will be signed out of both the portal and OpenBoxes simultaneously.
Password Policies
Lift enforces the following password requirements for all accounts:
- Minimum 12 characters
- At least three of these four: an uppercase letter, a lowercase letter, a number, a special character
- Cannot be the same as your username
- Cannot reuse any of your last 10 passwords
These requirements are set platform-wide and are not currently customisable per account.
Password Reset
If you forget your password:
- Click Forgot password? on the login page
- Enter your email address
- Check your inbox for a reset link (valid for 24 hours)
- Set a new password that meets the policy requirements
Connecting an External Identity Provider
Not available yet — on any tier. Connecting your own corporate identity provider (Okta, Azure AD / Entra ID, Google Workspace, any OIDC or SAML 2.0 provider) is planned post-launch and is not offered on Shared, Dedicated or Enterprise today. There is no Settings > SSO page in the portal.
If corporate-IdP federation is a hard requirement for your organisation, tell us before you sign up — talk to us via the chat on our site or Contact Sales, and we will be straight with you about timing rather than sell you a roadmap item.
What you can use today: every Lift account already signs in through our own single sign-on (see above), which covers the portal and OpenBoxes with one credential, and supports Google, Microsoft and GitHub as sign-in methods.
Multi-Factor Authentication
Lift supports multi-factor authentication (MFA) through Keycloak. Users can enable MFA on their account by:
- Signing into the portal
- Going to Account > Security
- Clicking Enable MFA
- Scanning the QR code with an authenticator app (Google Authenticator, Authy, etc.)
Organisation-wide MFA enforcement is not available yet; MFA is enabled per user, by that user.
Troubleshooting
"Access Denied" after signing in
Make sure the email address on your Google, Microsoft or GitHub account matches the email on your Lift invitation. Email matching is case-insensitive.
Session expired unexpectedly
Lift sessions are long-lived, but signing out in one place signs you out of both the portal and OpenBoxes. If you are being signed out more often than expected, contact support.