Internal users refer to members who have registered in the Dify Enterprise workspace or have been added in the admin backend.Workspace
The Callback URLs for Workspace and Webapp SSO are different, please note the distinction.
External users refer to members who have not joined the Dify Enterprise system.Web App
The Web App Callback URL for this permission scope is different from the Web App for internal users, please note the distinction.⚠️ Important Notes For security reasons, some identity providers (IDP) disable SSO authentication in iframe pages. This may affect situations where WebApps are embedded in other web pages. You need to check the identity provider’s (IDP) CSP: frame-ancestors configuration to ensure this feature works properly. For detailed instructions, please refer to this documentation. Here are the different security policies provided by various IDP vendors: