Single Sign-On

OpenBoxes Lift includes built-in single sign-on (SSO) powered by Keycloak. Every Lift account benefits from SSO — you sign in once and get access to both the Lift portal and your OpenBoxes instance without re-entering credentials.

How SSO Works#

When you sign in at app.openboxes.cloud, Keycloak (hosted at auth.openboxes.cloud) handles the authentication. Here is the flow:

  1. You enter your email and password on the Lift login page
  2. Keycloak verifies your credentials and creates a session
  3. You are signed into the Lift portal
  4. When you click Launch OpenBoxes, the portal uses your existing session to authenticate you with OpenBoxes automatically
  5. OpenBoxes opens in a new tab — no second login required

This means your team only needs to remember one set of credentials for everything on the Lift platform.

Session Management#

Session Duration#

Your portal session stays active as long as you are using the platform. Sessions expire after a period of inactivity:

Setting Standard sign-in With "Remember me"
Session timeout (idle) 14 days 7 days
Session maximum 30 days 30 days

Your OpenBoxes instance keeps its own session, which times out after 2 hours without activity. When a session expires you are redirected to the login page; sign in again and continue where you left off (unsaved edits in an open form are not preserved).

Signing Out#

Clicking Sign Out in the portal terminates your SSO session across all Lift services. You will be signed out of both the portal and OpenBoxes simultaneously.

Password Policies#

Lift enforces the following password requirements for all accounts:

  • Minimum 12 characters
  • At least three of these four: an uppercase letter, a lowercase letter, a number, a special character
  • Cannot be the same as your username
  • Cannot reuse any of your last 10 passwords

These requirements are set platform-wide and are not currently customisable per account.

Password Reset#

If you forget your password:

  1. Click Forgot password? on the login page
  2. Enter your email address
  3. Check your inbox for a reset link (valid for 24 hours)
  4. Set a new password that meets the policy requirements

Connecting an External Identity Provider#

Not available yet — on any tier. Connecting your own corporate identity provider (Okta, Azure AD / Entra ID, Google Workspace, any OIDC or SAML 2.0 provider) is planned post-launch and is not offered on Shared, Dedicated or Enterprise today. There is no Settings > SSO page in the portal.

If corporate-IdP federation is a hard requirement for your organisation, tell us before you sign up — talk to us via the chat on our site or Contact Sales, and we will be straight with you about timing rather than sell you a roadmap item.

What you can use today: every Lift account already signs in through our own single sign-on (see above), which covers the portal and OpenBoxes with one credential, and supports Google, Microsoft and GitHub as sign-in methods.

Multi-Factor Authentication#

Lift supports multi-factor authentication (MFA) through Keycloak. Users can enable MFA on their account by:

  1. Signing into the portal
  2. Going to Settings > Security
  3. Clicking Enable MFA
  4. Scanning the QR code with an authenticator app (Google Authenticator, Authy, etc.)

MFA is optional for every customer role, including the account owner and Admins: each person enrols themselves from Settings > Security. Organisation-wide enforcement is not available.

Troubleshooting#

"Access Denied" after signing in#

Make sure the email address on your Google, Microsoft or GitHub account matches the email on your Lift invitation. Email matching is case-insensitive.

Session expired unexpectedly#

Lift sessions are long-lived, but signing out in one place signs you out of both the portal and OpenBoxes. If you are being signed out more often than expected, contact support.