Currently supports Google/Azure/Okta/Auth0 for Single Sign-On. We don't maintain passwords for users. If a user doesn't have Single Sign-On, then they can use magic email links for login.
Credentials specific to external integrations are stored as encrypted using AES with GCM.