Differences
This shows you the differences between two versions of the page.
| Next revision | Previous revision | ||
| developers:admin:sso [2026/09/29 12:29] – created chad | developers:admin:sso [2026/09/29 14:12] (current) – [Common Provider Values] chad | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| ====== SSO Integration ====== | ====== SSO Integration ====== | ||
| - | T4 supports single sign-on (SSO) so your users can log in with your own identity provider (IdP) using [[https:// | + | T4 supports single sign-on (SSO), letting |
| - | Integrating SSO involves | + | Integrating SSO takes three steps: |
| - | - **Tell us about your identity provider** so we can register it and assign it to your firm. | + | - Send your identity provider |
| - | - **Link each T4 user** to their identity in that provider, using the standard user endpoints. | + | - Link each T4 user to their identity in that provider. |
| - | - **Send the OIDC token at login** from your application | + | - Send the OIDC token at login instead of a password. |
| - | + | ||
| - | < | + | |
| - | Registering a provider and assigning it to a firm are performed by T4 CTS Admin. As an integrator you supply the provider details once, then set the per-user link for each user through the onboarding and user endpoints described below. | + | |
| - | </ | + | |
| ===== What We Support ===== | ===== What We Support ===== | ||
| - | * **Protocol: | + | * **Protocol: |
| * **Providers: | * **Providers: | ||
| - | * **Validation: | ||
| - | ===== 1. Identity | + | ===== 1. Send Us Your Provider Details ===== |
| - | Send the following to T4 once per identity provider. The same provider can be reused across multiple firms on the same IdP. | + | Email the following to T4.[email protected]. T4 will confirm once the provider is set up. |
| | **Item** | **Description** | | | **Item** | **Description** | | ||
| | Name | A short label for the provider, e.g. '' | | Name | A short label for the provider, e.g. '' | ||
| | Vendor | Okta, Entra ID, AD FS, Ping Identity, Google, Keycloak, or Generic OIDC. | | | Vendor | Okta, Entra ID, AD FS, Ping Identity, Google, Keycloak, or Generic OIDC. | | ||
| - | | Issuer URL | The '' | + | | Issuer URL | The '' |
| - | | JWKS URI | The URL of your JSON Web Key Set. Always listed | + | | JWKS URI | The URL of your JSON Web Key Set. Listed |
| - | | Subject claim | The claim that uniquely identifies a user. Use '' | + | | Subject claim | The claim that uniquely identifies a user. Use '' |
| - | < | + | < |
| - | The **Issuer URL must match the '' | + | The Issuer URL must match the '' |
| </ | </ | ||
| - | |||
| - | Once you send these, T4 registers the provider and assigns it to your firm. For reference, the registration T4 performs on your behalf is: | ||
| - | |||
| - | < | ||
| - | POST https:// | ||
| - | |||
| - | { | ||
| - | " | ||
| - | " | ||
| - | " | ||
| - | " | ||
| - | " | ||
| - | " | ||
| - | " | ||
| - | } | ||
| - | </ | ||
| - | |||
| - | ==== Common Provider Values ==== | ||
| | **Provider** | **Issuer** | **Subject claim** | **JWKS URI** | | | **Provider** | **Issuer** | **Subject claim** | **JWKS URI** | | ||
| - | | Entra ID | '' | + | | Entra ID | '' |
| - | | Okta | '' | + | | Okta | '' |
| - | | Google | '' | + | | Google | '' |
| - | | AD FS | '' | + | | AD FS | '' |
| - | | Ping Identity | '' | + | | Ping Identity | '' |
| ===== 2. Link Each User to Their SSO Identity ===== | ===== 2. Link Each User to Their SSO Identity ===== | ||
| - | A T4 user is linked to their IdP identity | + | Link a user by adding |
| - | | **Field** | **Description** | **Required** | | + | | **Field** | **Description** | |
| - | | issuer | The provider' | + | | issuer | The provider' |
| - | | subject | The subject-claim value ('' | + | | subject | The subject-claim value ('' |
| - | At login, T4 matches the '' | ||
| - | |||
| - | < | ||
| - | '' | ||
| - | </ | ||
| - | You can set the link when onboarding | + | Set the link when onboarding, when creating a user, or on an existing user. |
| ==== During Onboarding ==== | ==== During Onboarding ==== | ||
| - | Add an '' | + | Add '' |
| < | < | ||
| Line 121: | Line 92: | ||
| ==== On an Existing User ==== | ==== On an Existing User ==== | ||
| - | |||
| - | Use PATCH to add or change the link for a user that already exists: | ||
| < | < | ||
| Line 136: | Line 105: | ||
| < | < | ||
| - | To **remove** an SSO link, PATCH with an empty '' | + | To remove |
| </ | </ | ||
| - | ==== Finding a User's Subject Value ==== | + | ===== 3. Logging In with SSO ===== |
| - | Most IdPs let an administrator list subject values in bulk (the Object ID in Entra ID, the user ID in Okta, the numeric account ID in Google). For a single user, have them sign in to any application on that IdP and decode the resulting token at '' | + | Log the user in with the standard [[developers: |
| - | <bootnote> | + | <code> |
| - | For Entra ID use the '' | + | // ClientMessage |
| - | </bootnote> | + | login_request { |
| - | + | | |
| - | ===== 3. Logging In with SSO ===== | + | app_name: " |
| - | + | app_license: | |
| - | Once the provider is assigned to your firm and a user is linked, your application logs the user in by sending the OIDC **ID token** from your IdP in the T4 login request, in place of a password. T4 then: | + | price_format: |
| + | } | ||
| + | </ | ||
| - | - Reads the '' | + | T4 validates the token (signature, issuer, and expiry) and signs in the user whose '' |
| - | - Fetches the provider' | + | |
| - | - Reads the subject claim ('' | + | |
| - | - Loads that user through | + | |
| - | If no provider, no link, or an invalid token is found, the login is rejected. | ||
| ===== Checklist ===== | ===== Checklist ===== | ||
| - | * Provider details sent to T4: issuer, JWKS URI, subject claim, and vendor. | + | * Provider details sent to T4.[email protected]. |
| - | * Provider registered and assigned to your firm (confirmed by T4). | + | * Every SSO user linked |
| - | * Every SSO user has an '' | + | * At least one successful test login before go-live. |
| - | * At least one successful test login completed | + | |