OIDC redirect
Your password stays with the identity provider.
RetentionOps uses Authorization Code with PKCE. The application receives scoped tokens only, never your credentials.
New to RetentionOps? Create an account
A secure session from the identity provider to your organization.
Sign-in happens on the RetentionOps identity service, at an origin separate from the application. The application never sees your password and refuses access without an active organization.
- Authorization code protected by PKCE
- Password kept by the identity service
- Session limited to your organization
No password is sent to RetentionOps.
Local RetentionOps environment · encrypted connection required