Sign-in methods & passwords
Configure how people sign in to Tessera under Settings → Authentication. Tessera supports two sign-in methods: a local username & password, and OIDC single sign-on with your identity provider.
Enforcing single sign-on
Section titled “Enforcing single sign-on”Turn the Password login switch off to require everyone to sign in through your identity provider. You can only disable password login while at least one OIDC provider is enabled — otherwise nobody could get in.
When password login is off, the sign-in page shows no password form:
- One OIDC provider — users are sent straight to it.
- Several providers — users pick one from a list of buttons.
Users created through OIDC never have a password, so this has no effect on them.
Break-glass recovery
Section titled “Break-glass recovery”If SSO ever becomes unavailable while password login is off (for example your identity provider is down, or misconfigured), you can temporarily re-enable password sign-in from the controller host:
- Set the environment variable
TESSERA_PASSWORD_LOGIN=trueon the controller and restart it. Password sign-in is now forced on for everyone, regardless of the switch. The controller logs a warning at startup while this is active. - Sign in with a password, fix your OIDC configuration (or turn the Password login switch back on).
- Remove the environment variable and restart the controller to return to the enforced setting.
Because this requires access to the server and a restart, it can’t be used by anyone reaching the controller only over the network.
Changing your own password
Section titled “Changing your own password”Any user who signs in with a password can change it: click the key icon in the bottom-left of the console, next to sign-out. Changing your password signs you out of all your other sessions.
Passwords must be at least 8 characters — enforced both when a user changes their own and when an administrator resets one.
Users who sign in through SSO have no password, so the option isn’t shown for them.
Resetting a user’s password
Section titled “Resetting a user’s password”Under Users, choose Reset password for a user and set a temporary password to hand to them. On their next sign-in — in the desktop app or the web console — they must choose a new password before they can do anything else. Their existing sessions are ended immediately.
- The option is disabled for SSO users (they have no password).
- Only an administrator can reset another administrator’s password, and you cannot reset the password of the administrator who granted you your role (see Administrators).
The forced change is enforced by the server: a temporary password cannot be used to connect to any target or make changes until it has been replaced.
Sessions & devices
Section titled “Sessions & devices”The desktop app and CLI bind an account to one device at a time. Signing in from a new device takes the account over and ends the previous device’s sessions, so a shared or stolen login can’t run in two places at once. (The web console isn’t device-bound.) Headless access tokens are device-bound separately, on their own first-use machine.
If your plan is out of seats, interactive sign-in is refused (“account locked: this Tessera plan has no free seats”) until a seat is freed or added — see Licensing & activation.
We would like to count visits with Google Analytics, which needs a cookie. Nothing is loaded and nothing is stored unless you accept. What this sets.