Platform Settings

Configure platform-wide defaults for every tenant

Authentication Providers
Basic only

Platform defaults apply across all tenants unless a tenant or organization overrides them with its own settings.

Username and password login against accounts stored in this platform. Recommended to keep enabled so administrators can always sign in even if an external provider is misconfigured or temporarily unavailable.


Lets anyone with a Google or Google Workspace account sign in. Create an OAuth 2.0 Client ID of type Web application in the Google Cloud console.

Register these in the Google OAuth client:
Step-by-step setup guide
  1. Open the Google Cloud console and create (or pick) a project.
  2. Configure the OAuth consent screen — choose Internal for Workspace-only, or External for any Google account.
  3. Go to CredentialsCreate credentialsOAuth client IDWeb application.
  4. Add the Authorized redirect URI and JavaScript origin shown above.
  5. Copy the generated Client ID and Client secret into the fields below.
  6. Enable the switch and save. Requested scopes: openid email profile.
Ends in .apps.googleusercontent.com. From the OAuth client “Client ID” field.
Shown once when you create the OAuth client (starts with GOCSPX-). Stored encrypted.

Lets users sign in with a Microsoft Entra ID (Azure AD), Microsoft 365 or personal Microsoft account. Register an application in the Microsoft Entra admin center and add a Web redirect URI.

Register this as a Web redirect URI:
Step-by-step setup guide
  1. Open Entra → App registrations and choose New registration.
  2. Under Supported account types pick who may sign in (single tenant, any org, or personal accounts too).
  3. Set Redirect URI platform to Web and paste the callback URI shown above.
  4. From the app Overview, copy the Application (client) ID and the Directory (tenant) ID into the fields below.
  5. Go to Certificates & secretsNew client secret, then copy its Value (not the Secret ID) below.
  6. Under API permissions ensure the delegated Microsoft Graph scopes openid, email, profile are present (added by default).
  7. Enable the switch and save.
The Application (client) ID (a GUID) from the app registration Overview page.
The secret Value from Certificates & secrets (copy it immediately — it is shown only once, and secrets expire). Stored encrypted.
The Directory (tenant) ID (a GUID) to restrict sign-in to one organization, or a keyword: common (any Microsoft account), organizations (any work/school account) or consumers (personal accounts only).
User Registration
Disabled

Controls whether visitors can create their own accounts. When disabled, the "Create an account" option is hidden and self-registration is rejected.

Per-tenant registration mode still applies once enabled.
Git Providers

Master gate for external git hosting. Enable the forges that organizations may host books on. Internal (LOCAL) storage is always available. Tenants can further disable any provider you enable here.

AI Settings
Not configured

Platform-wide default AI provider. Tenants and organizations inherit this unless they configure their own.

Used for semantic search. Leave blank for the provider default.
Branding
Not configured

Platform-wide default brand (logo, colors, fonts). Tenants and organizations inherit this unless they override it.

Shown in the navigation bar and page titles.
No logo — the default icon is used.
PNG/SVG, under 256 KB. Uploaded images are embedded inline.
Favicon preview No favicon — the default is used.