Single Sign-On
OpenBoxes Lift includes built-in single sign-on (SSO) powered by Keycloak. Every Lift account benefits from SSO — you sign in once and get access to both the Lift portal and your OpenBoxes instance without re-entering credentials.
How SSO Works#
When you sign in at app.openboxes.cloud, Keycloak (hosted at auth.openboxes.cloud) handles the authentication. Here is the flow:
- You enter your email and password on the Lift login page
- Keycloak verifies your credentials and creates a session
- You are signed into the Lift portal
- When you click Launch OpenBoxes, the portal uses your existing session to authenticate you with OpenBoxes automatically
- OpenBoxes opens in a new tab — no second login required
This means your team only needs to remember one set of credentials for everything on the Lift platform.
Session Management#
Session Duration#
Your portal session stays active as long as you are using the platform. Sessions expire after a period of inactivity:
| Setting | Standard sign-in | With "Remember me" |
|---|---|---|
| Session timeout (idle) | 14 days | 7 days |
| Session maximum | 30 days | 30 days |
Your OpenBoxes instance keeps its own session, which times out after 2 hours without activity. When a session expires you are redirected to the login page; sign in again and continue where you left off (unsaved edits in an open form are not preserved).
Signing Out#
Clicking Sign Out in the portal terminates your SSO session across all Lift services. You will be signed out of both the portal and OpenBoxes simultaneously.
Password Policies#
Lift enforces the following password requirements for all accounts:
- Minimum 12 characters
- At least three of these four: an uppercase letter, a lowercase letter, a number, a special character
- Cannot be the same as your username
- Cannot reuse any of your last 10 passwords
These requirements are set platform-wide and are not currently customisable per account.
Password Reset#
If you forget your password:
- Click Forgot password? on the login page
- Enter your email address
- Check your inbox for a reset link (valid for 24 hours)
- Set a new password that meets the policy requirements
Connecting an External Identity Provider#
Not available yet — on any tier. Connecting your own corporate identity provider (Okta, Azure AD / Entra ID, Google Workspace, any OIDC or SAML 2.0 provider) is planned post-launch and is not offered on Shared, Dedicated or Enterprise today. There is no Settings > SSO page in the portal.
If corporate-IdP federation is a hard requirement for your organisation, tell us before you sign up — talk to us via the chat on our site or Contact Sales, and we will be straight with you about timing rather than sell you a roadmap item.
What you can use today: every Lift account already signs in through our own single sign-on (see above), which covers the portal and OpenBoxes with one credential, and supports Google, Microsoft and GitHub as sign-in methods.
Multi-Factor Authentication#
Lift supports multi-factor authentication (MFA) through Keycloak. Users can enable MFA on their account by:
- Signing into the portal
- Going to Settings > Security
- Clicking Enable MFA
- Scanning the QR code with an authenticator app (Google Authenticator, Authy, etc.)
MFA is optional for every customer role, including the account owner and Admins: each person enrols themselves from Settings > Security. Organisation-wide enforcement is not available.
Troubleshooting#
"Access Denied" after signing in#
Make sure the email address on your Google, Microsoft or GitHub account matches the email on your Lift invitation. Email matching is case-insensitive.
Session expired unexpectedly#
Lift sessions are long-lived, but signing out in one place signs you out of both the portal and OpenBoxes. If you are being signed out more often than expected, contact support.