Mockoon Pro supports two authentication modes: Local database and OpenID Connect (OIDC) Single Sign-On. Public registration is closed; new users join via single-use invitation links or through enterprise SSO.

In local authentication mode, user accounts and credentials are saved in your local database. Users sign in at /login with their email and password, and the team owner can generate invitation links from the Users (/users) page. This mode operates completely offline without external identity provider dependencies.
The Users page (/users) allows the team Owner to oversee team access:

For local accounts, invitations are the primary method for adding new team members.
💡Invitations are only applicable for local accounts and do not apply to users logging in via OIDC SSO.
/users).User or Owner).https://mockoon.company.com/invite?token=...).💡 Invitation links are valid for 7 days and expire automatically if unclaimed.
OIDC Single Sign-On delegates authentication to your Identity Provider (IdP) for centralized user lifecycle management, MFA, and access control.
Supported identity providers include Microsoft Entra ID, Okta, Keycloak, Google Workspace, Auth0, Ping Identity, and any provider supporting OpenID Connect Discovery (.well-known/openid-configuration).
mockoon.company.com with your own domain):
Copyhttps://mockoon.company.com/auth/oidc/callback
/settings).https://login.microsoftonline.com/<tenant-id>/v2.0 or https://auth.company.com/realms/mockoon).
Settings are verified and applied immediately without restarting the server.
When an existing user (such as the initial admin) logs in via OIDC with a verified email matching their local account, Mockoon automatically links their account, preserving their team role and environments.
Restrict invitations and logins to approved corporate email domains:
/settings).company.com, engineering.company.com).When set:
Leave empty to allow all email domains.
