Walks through a structured production readiness checklist for Scalekit SSO implementations. Use when the user says they are going live, launching to production, doing a pre-launch review, hardening their SSO setup, or wants to verify their Scalekit implementation is production-ready.
Work through each section in order — earlier sections are blockers for later ones.
state parameter in callbacks (CSRF protection)httpOnly, secure, and sameSite flagsJIT provisioning:
Admin portal:
Enterprise customers behind VPN or corporate firewall must whitelist:
| Domain | Purpose |
|---|---|
<your-env>.scalekit.com | Auth + admin portal |
cdn.scalekit.com | Static assets |
fonts.googleapis.com | Font resources |
Key metrics: