Step 1: Register Curator with your provider
Create a web application in your provider’s admin console. The guide lists the three values the provider asks for, each with a copy button:- Redirect URI: the Curator URL with
/user/oauthappended. Enter only this URI. - Post logout redirect URI: the Curator URL.
- Scopes:
openid profile email.
Step 2: Enter the provider details
The provider shows three values once the application exists. Enter them under OAuth / OpenID Connect below the guide:- Issuer URL: the provider’s issuer, for example
https://login.microsoftonline.com/<tenant>/v2.0for Entra ID orhttps://<subdomain>.okta.comfor Okta. Curator derives the discovery URL from it and shows the result under the field. - Client ID: the application’s client ID.
- Client secret: the application’s client secret. Curator stores it as a hidden value.
Step 3: Test and turn on
Click Test sign-in. Curator opens the provider in a new window and signs you in with the details you saved, but records nothing for other users. When the provider answers, the card lists the claims in the ID token and marks the one Curator will use as the username. Pick a different claim if your Tableau usernames do not match the marked one. Curator writes your choice to the Username claim field under Compatibility overrides. Save the settings to make OAuth the active sign-in method. If the test fails, the card shows the provider’s error text. The most common causes are a redirect URI that does not match step 1 exactly, a wrong client secret, and an issuer URL that fails the check in step 2.Users
Curator creates a user record the first time each person signs in. If Curator is connected to an analytics platform, it copies the display name and email from that platform during the same sign-in. No SCIM feed is needed. To stop Curator from creating accounts on sign-in, turn on Disable Just-in-time Provisioning of Curator Users under Access rules.Compatibility overrides
The Compatibility overrides section holds the switches for providers that do not follow the defaults:- Username claim: the claim Curator reads as the username. Leave it blank to use the provider’s
preferred_username, thenname,email,emails, andsubin that order. Google accounts useemail. - Use the hybrid flow (code + id_token): turn this on for providers that return the ID token with the authorization code.
- Omit the logout redirect URI: turn this on when the provider rejects a post-logout redirect, so Curator ends its own session and sends the user to the provider’s sign-out page without a return address.