Single sign-on over OpenID Connect, and SCIM
19 August 2026
An organization points Kemble at its identity provider and its people sign in there, routed by an email domain the organization has proved it owns. A connection stays off until somebody enables it.
SCIM 2.0 lets the directory add and deactivate people. Deactivating somebody ends their sessions in the same operation, not when a token happens to expire.