Skip to main content

9.0.0 - SAML and OIDC single sign-on for teams

What's new

Single sign-on for teams

Jetstream now supports single sign-on through SAML and OIDC. Team owners configure a provider (Okta, Microsoft Entra / Azure, Google Workspace, or a generic SAML/OIDC provider), verify one or more domains, and optionally enforce SSO for members. When members log in, Jetstream matches their email domain to a verified SSO configuration and sends them to the right identity provider.

See the SSO overview for setup walkthroughs per provider.

Audit logging on team changes

Every team related record update now creates an audit log entry. Team owners can review who changed what and when, including member role changes, SSO configuration edits, and domain verification updates.

Authenticator code grace period

If your authenticator app code rotates right as you submit it, Jetstream now allows a 30 second grace window instead of rejecting it immediately. You should see far fewer "invalid code" errors at rotation boundaries.

Login form quality of life

The login form no longer makes you wait for the bot-check challenge before submitting. You can submit right away, and Jetstream waits for the challenge to finish before starting the login. This makes password manager and autofill flows more reliable.

Other fixes

  • Package names with special characters no longer trigger "No package.xml found" errors when using Add to Changeset.

Why 9.0?

This is a major version bump because SSO changes how login, session, and team authentication work across the product. Existing users are unaffected. Sign-in still works exactly as before unless your team enrolls in SSO.