SSO Settings

The SSO Settings screen controls how the module behaves across all providers. Providers themselves are configured on the Providers screen; enforcement has its own page.

Setting Default Meaning
Button Visibility Everywhere Where sign-in buttons render
Enable OAuth2 Providers off Second switch for social providers
Allow Account Linking on [memb_sso_connect] works (still needs the shortcode placed)
Require Verified Email on Refuse logins whose email the provider has not verified
Force Re-Authentication off Always ask the provider for fresh credentials
Clock Skew Window 1 minute Tolerance for token timestamps

Button Visibility

Everywhere renders buttons on every surface: wp-login.php, the front-end login form, WooCommerce's login form, and the [memb_sso_login] shortcode. Admin login page only keeps buttons off your front-end and limits them to wp-login.php. Hidden renders nothing anywhere, the shape for enforcement-only installs where members start at their provider, not at your login page.

Enable OAuth2 Providers

Social providers carry more account-takeover risk than corporate directories, so they sit behind a second switch. Stored social providers and their buttons do nothing until this is on.

Allow Account Linking

Gates the [memb_sso_connect] shortcode. Turning it off stops new connections and disconnects; existing bindings keep working for sign-in.

Require Verified Email

Force Re-Authentication

By default, a member with a live session at their provider can approve your sign-in without re-entering credentials. Turning this on sends prompt=login on every sign-in, so the provider always asks. It is always sent for account linking regardless of this setting, since connecting an identity to an account should demand fresh proof.

Clock Skew Window

How far token timestamps can drift between your server and the provider's before verification fails. One minute handles nearly every real deployment; raise it only if a provider's clocks are genuinely off.

Reference OP (advanced mode)

A minimal built-in Identity Provider for rehearsals, described on the Providers page. It answers only requests from trusted IPs and expects a fixed client. Leave it off outside development.