Skip to main content
Yes, it can. SaaS site builders accept an external OpenID Connect provider in their own SSO settings, so no plugin is needed: Veriqa is connected as an ordinary OIDC provider.

What it takes

  1. The email scope. Shopify and Wix use the mail address as the key of the customer or site member account, so the platform needs the email claim. Allow email in the client’s AllowedScopes. The address comes from the Email channel — the messenger channels do not provide a mail address, so for such a client the user signs in through the Email channel. What each channel provides is in the channel catalogue.
  2. A public HTTPS address for Veriqa with a valid certificate. The platform calls discovery, token and userinfo from its own servers, so a local test stand will not do.
  3. The SSO settings on the platform side: a Client ID, a Client Secret and Veriqa’s discovery address. The platform generates the callback URL itself — add it to the client’s allowed redirect URIs.

Shopify

The feature is called “connect your own identity provider to customer accounts” and runs over OIDC. Shopify’s requirements for an external provider and how Veriqa meets them (checked with a full authorization code flow on the Email channel):
Veriqa has no RP-Initiated Logout: a customer signing out of the store does not end the session on the Veriqa side. revocation_endpoint (RFC 7009) revokes tokens — a different operation, and it does not satisfy this Shopify requirement. The full list of what is and is not supported is in OIDC and OAuth 2.0 support.
Shopify also has legacy mechanisms (Multipass, the Storefront API token flow), but its own documentation recommends moving off them to an external IdP — do not build on them.

Wix

Wix accepts an external provider over OIDC as well, and also without a plugin: its SSO settings take a Client ID, a Client Secret and a Config URL — Veriqa’s discovery address — and the platform pulls the rest itself. Field mapping in Wix is configurable. If site members are identified by their mail address, request the email scope just as for Shopify.

If you need a confirmed submission rather than a sign-in

If the goal is not “a member area on the platform” but “a confirmed submission”, no SSO settings are needed at all: a small server-side handler next to the form is enough, see Confirmed form submission.