What it takes
- The
emailscope. Shopify and Wix use the mail address as the key of the customer or site member account, so the platform needs theemailclaim. Allowemailin the client’sAllowedScopes. The address comes from the Email channel — the messenger channels do not provide a mail address, so for such a client the user signs in through the Email channel. What each channel provides is in the channel catalogue. - A public HTTPS address for Veriqa with a valid certificate. The platform calls discovery, token and userinfo from its own servers, so a local test stand will not do.
- The SSO settings on the platform side: a
Client ID, aClient Secretand Veriqa’s discovery address. The platform generates the callback URL itself — add it to the client’s allowed redirect URIs.
Shopify
The feature is called “connect your own identity provider to customer accounts” and runs over OIDC. Shopify’s requirements for an external provider and how Veriqa meets them (checked with a full authorization code flow on the Email channel):Shopify also has legacy mechanisms (Multipass, the Storefront API token flow), but its own
documentation recommends moving off them to an external IdP — do not build on them.
Wix
Wix accepts an external provider over OIDC as well, and also without a plugin: its SSO settings take aClient ID, a Client Secret and a Config URL — Veriqa’s discovery address — and the
platform pulls the rest itself.
Field mapping in Wix is configurable. If site members are identified by their mail address,
request the email scope just as for Shopify.