Skip to content
Docs

Restrict access to deployments with Passport

Passport is available on Enterprise plans

Those with the owner role can manage Passport

Passport lets you protect deployments with your own identity provider. Visitors authenticate with your identity provider before they can view a protected deployment.

Use Passport when you want visitors to sign in with an external identity provider, such as Microsoft Entra ID, Okta, or another OpenID Connect compatible provider. Vercel Connect stores the OAuth application configuration that talks to your identity provider.

Passport has two parts:

  • Vercel Connect application: The OAuth or OpenID Connect configuration that stores your identity provider's issuer, endpoints, client ID, and client secret.
  • Project or team setting: The Passport configuration that selects the Connect application and controls whether Passport is enabled.

When a visitor opens a protected deployment, Vercel redirects them to your identity provider. After the identity provider authenticates the visitor, Vercel validates the response and sets a session cookie for the protected deployment.

New to Passport? Set up Passport with an identity provider first, then return to the other guides when you need to use identity in application code.

For a URL that uses microfrontends routing, the default application's Passport configuration protects every path, including paths served by child applications. Configure Passport on the default application to protect the composed microfrontend experience.

Passport completes authentication at /.well-known/vercel/passport/callback on the requested hostname. Vercel handles this callback before routing to your application, so you do not need to create the path in the default or child application.

For URLs with microfrontends routing, child paths use the default application's Passport configuration. Child applications cannot have an independent Passport connection while they belong to the group.

The default application's Passport configuration does not protect a child application's direct domains. Protect those domains with another Deployment Protection method. To configure Passport on the child project, remove it from the group first.

Learn more about Deployment Protection and microfrontends.

When a visitor successfully authenticates to a Passport-protected project, Vercel records a passport-access-granted event in both the Activity Log and Audit Logs. The event identifies the visitor and records the protected hostname and project context.

In the Activity Log, select Filter by Event, then select passport-access-granted to view Passport access events.

Passport is available as an Enterprise feature. Contact your Vercel account team for pricing.

Last updated September 21, 2026

Was this helpful?

supported.