Recipes
Copy-pasteable patterns for the Thoryn platform.
Browse
Three recipe categories.
Pick the one that matches what you're integrating with.
Library · 31 recipes
Latest recipes.
Every recipe lives in the repo as MDX — readable, versioned, and reviewable like code.
- auth0-with-hub-upstream
auth0-with-hub-upstream
Add Thoryn Hub as a Custom OIDC connection in your existing Auth0 tenant
Customer keeps Auth0 as the user-facing IdP and adds Thoryn Hub as an upstream OIDC connection. The reverse of `auth0-as-source` — use it when migration is years away but EUDIW is needed today.
- auth0
- oidc
- idp
- hub-upstream
- okta-with-hub-upstream
okta-with-hub-upstream
Add Thoryn Hub as an OIDC IdP in your existing Okta tenant
Customer keeps Okta as the user-facing IdP and adds Thoryn Hub as an upstream OIDC identity provider — the EUDIW + verifiable-credential gateway behind the Okta login. The reverse of `okta`.
- okta
- oidc
- idp
- hub-upstream
- dotnet
dotnet
ASP.NET 8 — Hub login with `Microsoft.AspNetCore.Authentication.OpenIdConnect`
Wire OAuth2 / OIDC into an ASP.NET 8 app via the official OpenIdConnect handler. Five steps, ~20 lines of config.
- dotnet
- aspnet
- csharp
- oidc
- auth0-as-source
auth0-as-source
Auth0 as a Hub federation source — migration overlay
Federate Hub to an existing Auth0 tenant during a migration window. Customers stay logged in via Auth0; Hub takes over gradually.
- auth0
- oidc
- idp
- migration
- App connectors
App connectors
Cloudflare Access — Thoryn as a generic OIDC IdP
Cloudflare Access protects internal apps with identity-aware proxies. Thoryn as the IdP gates access to anything Cloudflare fronts.
- cloudflare
- oidc
- infra
- django
django
Django 5 — Hub login with `mozilla-django-oidc`
Wire OAuth2 / OIDC into a Django 5 app. Five steps, ~15 lines of settings.
- django
- python
- oidc
- express
express
Express — Hub login with `openid-client`
Add OIDC to an Express 4 / 5 app using the official Node OIDC library. ~40 lines of code.
- express
- node
- oidc
- App connectors
App connectors
Figma — SAML SSO via Thoryn
Figma Enterprise SSO via SAML. Use Thoryn's SAML bridge for OIDC ↔ SAML translation.
- figma
- saml
- productivity
- generic-oidc
generic-oidc
Generic OIDC IdP as a Hub federation member
Catch-all template for federating Hub to any OIDC-conformant IdP — public-cloud providers, regional IdPs, internal identity stacks.
- oidc
- idp
- generic
- generic-saml
generic-saml
Generic SAML 2.0 IdP as a Hub federation member
Federate Hub to any SAML 2.0 IdP — long-tail enterprise IdPs, custom corporate identity providers, ADFS, etc.
- saml
- idp
- generic
- App connectors
App connectors
GitHub Enterprise Cloud — Thoryn as the OIDC IdP
Configure GitHub Enterprise Cloud (with EMU) to authenticate users via Thoryn-issued OIDC tokens.
- github
- oidc
- dev-tooling
- App connectors
App connectors
GitLab — Thoryn as a generic OIDC provider
GitLab self-managed or SaaS Premium+ can use Thoryn as an OAuth2 / OIDC IdP via the omniauth_openid_connect strategy.
- gitlab
- oidc
- dev-tooling
- google-workspace
google-workspace
Google Workspace as a Hub federation member
Federate Hub to a Google Workspace tenant. Common at small-mid SaaS customers.
- google-workspace
- oidc
- idp
- App connectors
App connectors
HubSpot — SAML SSO via Thoryn
HubSpot Enterprise SSO. SAML 2.0 only; use Thoryn's SAML bridge.
- hubspot
- saml
- sales
- App connectors
App connectors
Intercom — SAML SSO via Thoryn
Intercom Premium SSO via SAML. Use Thoryn's SAML bridge.
- intercom
- saml
- support
- jumpcloud
jumpcloud
JumpCloud as a Hub federation member
Federate Hub to a JumpCloud directory. The simplest of the seven pre-built connectors — JumpCloud uses one global OAuth issuer, so only client-id and client-secret are needed.
- jumpcloud
- oidc
- idp
- keycloak
keycloak
Keycloak as a Hub federation member
Self-hosted shops federate their Keycloak realm into Hub via standard OIDC. Common at developer-heavy customers and EU public-sector orgs.
- keycloak
- oidc
- idp
- self-hosted
- App connectors
App connectors
Linear — SAML SSO via Thoryn
Linear Enterprise SSO via SAML. Use Thoryn's SAML-bridge federation member for OIDC ↔ SAML translation.
- linear
- saml
- productivity
- linkedin
linkedin
LinkedIn as a Hub federation member
Add LinkedIn social sign-in via OIDC. Two LinkedIn quirks shape the setup — email is a separate scope, sub is opaque per app.
- oidc
- social
- idp
- entra-id
entra-id
Microsoft Entra ID (Azure AD) as a Hub federation member
Federate Hub to an Entra ID tenant. Most-common enterprise scenario in DACH and the UK.
- entra-id
- azure-ad
- oidc
- idp
- next-js
next-js
Next.js — Hub-backed SSO in 5 minutes
Add OAuth 2.0 / OIDC login to a Next.js 15 App Router app via Hub. Five steps, ~30 lines of code.
- next-js
- react
- oidc
- app-router
- App connectors
App connectors
Notion — SAML SSO via Thoryn
Notion Enterprise SSO. Notion supports SAML only (no OIDC); the recipe uses Thoryn's SAML-bridge flow.
- notion
- saml
- productivity
- okta
okta
Okta as a Hub federation member (OIDC)
Federate Hub to an Okta tenant. Okta authenticates the user; Hub issues the OAuth2 / OIDC tokens to your relying parties.
- okta
- oidc
- idp
- rails
rails
Rails 7 — Hub login with `omniauth-openid_connect`
Wire OAuth2 / OIDC into a Rails 7 app via OmniAuth. Five steps, ~25 lines of config.
- rails
- ruby
- oidc
- react-spa
react-spa
React SPA — Hub login with `oidc-client-ts`
Wire OAuth2 / OIDC into a React 19 + Vite SPA using the standard browser library. Auth code with PKCE, no client secret.
- react
- vite
- oidc
- spa
- App connectors
App connectors
Salesforce — use Thoryn as an OpenID Connect Auth Provider
Configure Salesforce to accept Thoryn-issued OIDC tokens. Works with Sales Cloud, Service Cloud, Experience Cloud.
- salesforce
- oidc
- crm
- App connectors
App connectors
Slack — use Thoryn as the OIDC IdP
Pre-configured OIDC client for Slack. Customer pastes client_id/secret into Hub admin; Slack's custom IdP setup is filled in by claim.
- slack
- oidc
- communication
- spring-boot
spring-boot
Spring Boot 3 — Hub login with Spring Security OAuth2
Add OAuth 2.0 / OIDC to a Spring Boot 3 web app via Spring Security 6's OAuth2 client. Five steps, ~10 lines of YAML.
- spring-boot
- java
- kotlin
- oauth2
- App connectors
App connectors
Stripe Dashboard — SSO via Thoryn (SAML)
Stripe Dashboard SSO. Stripe supports SAML 2.0 only; OIDC is not exposed for Dashboard auth.
- stripe
- saml
- finance
- vue
vue
Vue 3 — Hub login with `oidc-client-ts`
Wire OAuth2 / OIDC into a Vue 3 + Vite app. Auth code with PKCE, composable for the rest of the app.
- vue
- vite
- oidc
- spa
- App connectors
App connectors
Zoom — Thoryn as an OAuth 2.0 IdP
Zoom Enterprise SSO via Thoryn. Workspace Admin pastes client credentials; users SSO into Zoom Web + Desktop + Mobile.
- zoom
- oidc
- communication