RetentionOps

OIDC redirect

Your password stays with the identity provider.

RetentionOps uses Authorization Code with PKCE. The application receives scoped tokens only, never your credentials.

New to RetentionOps? Create an account


A secure session from the identity provider to your organization.

Sign-in happens on the RetentionOps identity service, at an origin separate from the application. The application never sees your password and refuses access without an active organization.

  • Authorization code protected by PKCE
  • Password kept by the identity service
  • Session limited to your organization

No password is sent to RetentionOps.

Local RetentionOps environment · encrypted connection required