Comprehensive OAuth Single Sign-On plugin for Rise CRM with support for Google, Microsoft, Apple, Facebook, GitHub, and Envato. Streamline authentication with automatic account creation and attendance management.
Support for 6 major OAuth providers including Google, Microsoft, Apple, Facebook, GitHub, and Envato—all in one plugin.
Built with CSRF protection, state verification, and secure token handling to ensure your users' data is always protected.
Plug-and-play with RISE CRM; install, configure your OAuth providers, and you're ready to go—no developer required.
Support for both team members and clients with automatic account creation and optional attendance clock-in integration.
Users authenticate in seconds with their existing accounts
Leverage enterprise-grade OAuth security from trusted providers
Theme-aware UI that matches your RISE CRM installation
Auto clock-in and account creation reduce administrative overhead
Google, Microsoft, Apple, Facebook, GitHub, and Envato OAuth integration
Support for both team members and clients with configurable permissions
Automatic client account creation for new OAuth users
Auto clock-in for team members when enabled in settings
Adapts to Rise CRM theme colors and dark mode preferences
CSRF protection, state verification, and secure token handling
Simple setup with copy-to-clipboard redirect URIs
Full internationalization support for all features
Upload the plugin to /plugins/UltimateSSO/ and activate it from Settings > Plugins in your RISE CRM admin panel.
Set up OAuth credentials for your desired providers in Settings > Integrations > Ultimate SSO. Copy redirect URIs with one click.
Users can now sign in with their preferred OAuth provider. New client accounts are created automatically if enabled.
OpenID Connect protocol with email, name, and profile picture retrieval
Azure Active Directory integration for personal and organizational accounts
Privacy-focused Sign In with Apple using JWT token validation
Access to Facebook profile and email through Graph API
GitHub profile authentication with verified email retrieval
Envato Market user authentication with purchase history access
| Feature | Ultimate SSO | Traditional Auth |
|---|---|---|
| Multiple OAuth Providers | ||
| No Password Required | ||
| Auto Account Creation | ||
| Attendance Integration | ||
| Theme-Aware UI | Partial | |
| Security (CSRF, State Verification) | Basic |
Detailed step-by-step instructions for configuring each OAuth provider. Select a provider below to view its setup guide.
Standard OAuth 2.0 integration for Google accounts
How it works: Google OAuth uses the OpenID Connect protocol to authenticate users and retrieve their profile information including email, name, and profile picture.
Authorization URL: https://accounts.google.com/o/oauth2/auth
Token URL: https://oauth2.googleapis.com/token
Profile URL: https://www.googleapis.com/oauth2/v2/userinfo
Required Scopes: openid, email, profile
User ID, Email address, Full name, First/last name, Profile picture URL
Azure Active Directory integration for personal and organizational accounts
How it works: Microsoft OAuth integrates with Azure Active Directory to authenticate both personal Microsoft accounts and organizational accounts.
User ID, Email address, Display name, Given name, Surname
Privacy-focused authentication with JWT validation and email relay
How it works: Apple's Sign In with Apple provides privacy-focused authentication with optional email relay service and requires JWT token validation.
✓ HTTPS Required in production
✓ Custom redirect URI supports ngrok/staging environments
✓ Private key (.p8) can only be downloaded once from Apple
Graph API integration for social authentication
How it works: Facebook OAuth provides access to user's basic profile information and email through Facebook's Graph API.
User ID, Email address, Full name, Profile picture URL
Developer authentication with User-Agent requirements
How it works: GitHub OAuth authenticates developers and provides access to their profile. GitHub requires a User-Agent header for all API requests.
✓ User-Agent header required for all API requests
✓ Email may require separate /user/emails endpoint call
Marketplace authentication for Envato users and authors
How it works: Envato OAuth provides authentication for Envato Market users and access to their account information, purchase history, and marketplace activity.
✓ view_user_username - Access to username
✓ view_user_account - Access to account details
✓ view_user_purchases - Access to purchase history
✓ download_user_purchases - Access to purchase downloads
Our support team is ready to assist with any questions about OAuth provider setup or configuration. We typically respond within 24 hours.
Contact Support →