> ## Documentation Index
> Fetch the complete documentation index at: https://veriqa.app/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Shopify, Wix and other SaaS builders

> Can Veriqa be connected to a SaaS platform as its external sign-in provider, and what it takes: the email scope, a public address and the platform's SSO settings.

Yes, it can. SaaS site builders accept an external OpenID Connect provider in their own **SSO
settings**, so no plugin is needed: Veriqa is connected as an ordinary OIDC provider.

## What it takes

1. **The `email` scope.** Shopify and Wix use the mail address as the key of the customer or site
   member account, so the platform needs the `email` claim. Allow `email` in the client's
   `AllowedScopes`. The address comes from the Email channel — the messenger channels do not
   provide a mail address, so for such a client the user signs in through the Email channel. What
   each channel provides is in the [channel catalogue](/docs/guides/supported-channels).
2. **A public HTTPS address for Veriqa with a valid certificate.** The platform calls discovery,
   token and userinfo from its own servers, so a local test stand will not do.
3. **The SSO settings on the platform side:** a `Client ID`, a `Client Secret` and Veriqa's
   discovery address. The platform generates the callback URL itself — add it to the client's
   allowed redirect URIs.

## Shopify

The feature is called "connect your own identity provider to customer accounts" and runs over
OIDC. Shopify's requirements for an external provider and how Veriqa meets them (checked with a
full authorization code flow on the Email channel):

| Shopify requirement | Veriqa |
| - | - |
| Discovery endpoint | present |
| JWKS endpoint | present |
| Authorization code flow only | `response_types_supported: ["code"]` |
| PKCE `S256` for public clients | supported |
| RS/ES/PS/EdDSA signatures, HS256 forbidden | `RS256` |
| `sub`, `iss`, `aud`, `nonce` in the `id_token` | all present, `nonce` matches |
| `email` in the `id_token` | arrives with the `email` scope on the Email channel |
| `email_verified` is `true` | JSON boolean `true` |
| Refresh tokens (sessions up to 90 days) | the `refresh_token` grant with the `offline_access` scope |
| Discovery / token / userinfo answer in under a second | 0.26–0.29 s on a local installation |
| RP-Initiated Logout (`end_session_endpoint`) | **not supported** |

<Warning>
  Veriqa has no RP-Initiated Logout: a customer signing out of the store does not end the session
  on the Veriqa side. `revocation_endpoint` (RFC 7009) revokes tokens — a different operation, and
  it does not satisfy this Shopify requirement. The full list of what is and is not supported is in
  [OIDC and OAuth 2.0 support](/docs/reference/oidc-capabilities).
</Warning>

<Note>
  Shopify also has legacy mechanisms (Multipass, the Storefront API token flow), but its own
  documentation recommends moving off them to an external IdP — do not build on them.
</Note>

## Wix

Wix accepts an external provider over OIDC as well, and also without a plugin: its SSO settings
take a `Client ID`, a `Client Secret` and a **Config URL** — Veriqa's discovery address — and the
platform pulls the rest itself.

Field mapping in Wix is configurable. If site members are identified by their mail address,
request the `email` scope just as for Shopify.

## If you need a confirmed submission rather than a sign-in

If the goal is not "a member area on the platform" but "a confirmed submission", no SSO settings
are needed at all: a small server-side handler next to the form is enough, see
[Confirmed form submission](/docs/integrations/confirmed-form).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.