SSO Settings
The SSO Settings screen controls how the module behaves across all providers. Providers themselves are configured on the Providers screen; enforcement has its own page.
| Setting | Default | Meaning |
|---|---|---|
| Button Visibility | Everywhere | Where sign-in buttons render |
| Enable OAuth2 Providers | off | Second switch for social providers |
| Allow Account Linking | on | [memb_sso_connect] works (still needs the shortcode placed) |
| Require Verified Email | on | Refuse logins whose email the provider has not verified |
| Force Re-Authentication | off | Always ask the provider for fresh credentials |
| Clock Skew Window | 1 minute | Tolerance for token timestamps |
Button Visibility
Everywhere renders buttons on every surface: wp-login.php, the front-end login form, WooCommerce's login form, and the [memb_sso_login] shortcode. Admin login page only keeps buttons off your front-end and limits them to wp-login.php. Hidden renders nothing anywhere, the shape for enforcement-only installs where members start at their provider, not at your login page.
Enable OAuth2 Providers
Social providers carry more account-takeover risk than corporate directories, so they sit behind a second switch. Stored social providers and their buttons do nothing until this is on.
Allow Account Linking
Gates the [memb_sso_connect] shortcode. Turning it off stops new connections and disconnects; existing bindings keep working for sign-in.
Require Verified Email
Force Re-Authentication
By default, a member with a live session at their provider can approve your sign-in without re-entering credentials. Turning this on sends prompt=login on every sign-in, so the provider always asks. It is always sent for account linking regardless of this setting, since connecting an identity to an account should demand fresh proof.
Clock Skew Window
How far token timestamps can drift between your server and the provider's before verification fails. One minute handles nearly every real deployment; raise it only if a provider's clocks are genuinely off.
Reference OP (advanced mode)
A minimal built-in Identity Provider for rehearsals, described on the Providers page. It answers only requests from trusted IPs and expects a fixed client. Leave it off outside development.