diff --git a/docs/documentation/platform/sso/general-oidc/group-membership-mapping.mdx b/docs/documentation/platform/sso/general-oidc/group-membership-mapping.mdx
new file mode 100644
index 000000000..fd405fdfc
--- /dev/null
+++ b/docs/documentation/platform/sso/general-oidc/group-membership-mapping.mdx
@@ -0,0 +1,55 @@
+---
+title: "General OIDC Group Membership Mapping"
+sidebarTitle: "Group Membership Mapping"
+description: "Learn how to sync OIDC group members to matching groups in Infisical."
+---
+
+You can have Infisical automatically sync group
+memberships between your OIDC provider and Infisical by configuring a `groups` claim on your provider tokens.
+When a user logs in via OIDC, they will be added to Infisical groups that are present in their OIDC `groups` claim,
+and removed from any Infisical groups not present in the claim.
+
+
+ When enabled, manual
+ management of Infisical group memberships will be disabled.
+
+
+
+ Group membership changes in your OIDC provider only sync with Infisical when a
+ user logs in via OIDC. For example, if you remove a user from a group in your OIDC provider,
+ this change will not be reflected in Infisical until their next OIDC login.
+ To ensure this behavior, Infisical recommends enabling Enforce OIDC SSO in the OIDC settings.
+
+
+
+
+
+ To enable OIDC Group Membership Mapping, you must configure a `groups` claim in your OIDC provider.
+
+ Add a `groups` property with a list of the user's OIDC group names to your token.
+
+ Example of expected token payload:
+ ```json
+ {
+ // "email": "john@provider.com",
+ // "given_name": "John",
+ // ...other claims
+ "groups": ["Billing Group", "Sales Group"]
+ }
+ ```
+
+
+ Setup varies between OIDC providers. Please refer to your OIDC provider's documentation for more information.
+
+
+
+ 2.1. In Infisical, create any groups you would like to sync users to. Make sure the name of the Infisical group is an exact match of the OIDC group name.
+ 
+
+ 2.2. Next, enable **OIDC Group Membership Mapping** on the **Single Sign-On (SSO)** page under the **General** tab.
+ 
+
+ 2.3. The next time a user logs in they will be synced to their matching OIDC groups.
+ 
+
+
\ No newline at end of file
diff --git a/docs/documentation/platform/sso/general-oidc.mdx b/docs/documentation/platform/sso/general-oidc/overview.mdx
similarity index 92%
rename from docs/documentation/platform/sso/general-oidc.mdx
rename to docs/documentation/platform/sso/general-oidc/overview.mdx
index a10b05cfc..76ac982f8 100644
--- a/docs/documentation/platform/sso/general-oidc.mdx
+++ b/docs/documentation/platform/sso/general-oidc/overview.mdx
@@ -1,5 +1,6 @@
---
title: "General OIDC"
+sidebarTitle: "Overview"
description: "Learn how to configure OIDC for Infisical SSO with any OIDC-compliant identity provider"
---
@@ -29,7 +30,7 @@ Prerequisites:
2.1. Back in Infisical, head to the **Single Sign-On (SSO)** page and select the **General** tab. Select **Connect** for **OIDC**.
- 
+ 
2.2. You can configure OIDC either through the Discovery URL (Recommended) or by inputting custom endpoints.
@@ -39,10 +40,10 @@ Prerequisites:
Note that the Discovery Document URL typically takes the form: `https:///.well-known/openid-configuration`.
- 
+ 
To configure OIDC via the custom endpoints, set the **Configuration Type** field to **Custom** and input the required endpoint fields.
- 
+ 
2.3. Select the appropriate JWT signature algorithm for your IdP. Currently, the supported options are RS256, RS512, HS256, and EdDSA.
@@ -55,7 +56,7 @@ Prerequisites:
Enabling OIDC SSO allows members in your organization to log into Infisical via the configured Identity Provider
- 
+ 
diff --git a/docs/mint.json b/docs/mint.json
index 61b89c609..5335c7423 100644
--- a/docs/mint.json
+++ b/docs/mint.json
@@ -266,14 +266,25 @@
"documentation/platform/sso/google-saml",
"documentation/platform/sso/auth0-saml",
{
- "group": "Keycloak OIDC",
+ "group": "OIDC",
"pages": [
- "documentation/platform/sso/keycloak-oidc/overview",
- "documentation/platform/sso/keycloak-oidc/group-membership-mapping"
+ {
+ "group": "Keycloak OIDC",
+ "pages": [
+ "documentation/platform/sso/keycloak-oidc/overview",
+ "documentation/platform/sso/keycloak-oidc/group-membership-mapping"
+ ]
+ },
+ "documentation/platform/sso/auth0-oidc",
+ {
+ "group": "General OIDC",
+ "pages": [
+ "documentation/platform/sso/general-oidc/overview",
+ "documentation/platform/sso/general-oidc/group-membership-mapping"
+ ]
+ }
]
- },
- "documentation/platform/sso/auth0-oidc",
- "documentation/platform/sso/general-oidc"
+ }
]
},
{