Icinga sso

I have a running sso installation with mod_auth_openidc.
Now I still have some problems to bypass sso and use the normal login with user and password for some special locally in icingaweb2 defined users and for api-calls. Maybe External auth and director api can help? Anyone has a good solution here? I have configured the apache webserver to not use sso for some users that use basic auth with an IF in the apache configuration, but I think, this is not really a good solution here and it only works for the api-calls and not in the browser.