Outcome of the 2026-08-10 SSO evaluation (intent #4 of the consolidation-recovered intents): the provider-switch question is settled — OntoKit stays on Zitadel (verdict: Reject the switch; identity IDs already live in trust/audit data post-flip, Zitadel is the CDCF-wide umbrella IdP per #274, and the recorded pain is plumbing, not provider fit).
The original outline's real concern ("or maybe simply Google login") is served additively: federate Google INTO Zitadel as an external IdP — users get "Sign in with Google," the app keeps one issuer and stable Zitadel user IDs. Auto-create + auto-link on verified email; no auth-code changes expected in either repo.
Trigger-gated: implement when login friction becomes a live user complaint, not before.
Plan (implementation-ready): ontokit-web docs/plans/2026-08-10-001-feat-google-federation-zitadel-plan.md (branch feat/roundup-brainstorm). Key caveat to verify at implementation time: the deployed Login V2 social-callback URI (the one under-corroborated external claim).
Outcome of the 2026-08-10 SSO evaluation (intent #4 of the consolidation-recovered intents): the provider-switch question is settled — OntoKit stays on Zitadel (verdict: Reject the switch; identity IDs already live in trust/audit data post-flip, Zitadel is the CDCF-wide umbrella IdP per #274, and the recorded pain is plumbing, not provider fit).
The original outline's real concern ("or maybe simply Google login") is served additively: federate Google INTO Zitadel as an external IdP — users get "Sign in with Google," the app keeps one issuer and stable Zitadel user IDs. Auto-create + auto-link on verified email; no auth-code changes expected in either repo.
Trigger-gated: implement when login friction becomes a live user complaint, not before.
Plan (implementation-ready): ontokit-web
docs/plans/2026-08-10-001-feat-google-federation-zitadel-plan.md(branch feat/roundup-brainstorm). Key caveat to verify at implementation time: the deployed Login V2 social-callback URI (the one under-corroborated external claim).