This is a preview of the Storyblok Website with Draft Content

JoyConf 2026 is back. Content Confidence. Human Connection. Save your spot!

[Draft]Premium Plan

Self-service SSO and OAuth 2.0 Scoped Grants

  • Extensions
  • Security
  • Developer Experience
Books and Storyblok Logo

Two changes landing together to harden identity and integration security. Organizations can now configure and manage SSO directly from Organization > Settings > SSO Settings. Primary and additional login domains, IdP metadata, SAML attribute mapping, and Entra ID or generic SAML 2.0 are editable in place, with no support ticket needed for setup, domain renames, certificate rotation, or metadata refresh.

Custom integrations connecting to the Management API now use OAuth 2.0 Scoped Grants instead of long-lived personal access tokens. Users see and approve exactly what an integration can do on a consent page, with scopes at the resource-action level on a publish, write, read hierarchy, per-space selection, short-lived access tokens, rotating refresh tokens, and immediate revocation.

Self-service SSO and OAuth 2.0 Scoped Grants is both available on Premium and Enterprise.