Differences
This shows you the differences between two versions of the page.
| Both sides previous revision Previous revision Next revision | Previous revision | ||
| developers:admin:sso [2026/09/29 12:37] – chad | developers:admin:sso [2026/09/29 14:12] (current) – [Common Provider Values] chad | ||
|---|---|---|---|
| Line 25: | Line 25: | ||
| | Subject claim | The claim that uniquely identifies a user. Use '' | | Subject claim | The claim that uniquely identifies a user. Use '' | ||
| - | < | + | < |
| The Issuer URL must match the '' | The Issuer URL must match the '' | ||
| </ | </ | ||
| - | |||
| - | ==== Common Provider Values ==== | ||
| | **Provider** | **Issuer** | **Subject claim** | **JWKS URI** | | | **Provider** | **Issuer** | **Subject claim** | **JWKS URI** | | ||
| - | | Entra ID | '' | + | | Entra ID | '' |
| - | | Okta | '' | + | | Okta | '' |
| - | | Google | '' | + | | Google | '' |
| - | | AD FS | '' | + | | AD FS | '' |
| - | | Ping Identity | '' | + | | Ping Identity | '' |
| ===== 2. Link Each User to Their SSO Identity ===== | ===== 2. Link Each User to Their SSO Identity ===== | ||
| Line 46: | Line 43: | ||
| | subject | The subject-claim value ('' | | subject | The subject-claim value ('' | ||
| - | < | ||
| - | '' | ||
| - | </ | ||
| Set the link when onboarding, when creating a user, or on an existing user. | Set the link when onboarding, when creating a user, or on an existing user. | ||
| Line 114: | Line 108: | ||
| </ | </ | ||
| - | ==== Finding a User's Subject Value ==== | + | ===== 3. Logging In with SSO ===== |
| - | Most IdPs let an admin list subject values in bulk (Object ID in Entra ID, user ID in Okta, numeric account ID in Google). For a single user, have them sign in and decode the token at '' | + | Log the user in with the standard [[developers: |
| - | <bootnote> | + | <code> |
| - | For Entra ID use '' | + | // ClientMessage |
| - | </bootnote> | + | login_request { |
| + | id_token: " | ||
| + | app_name: " | ||
| + | app_license: | ||
| + | price_format: | ||
| + | } | ||
| + | </code> | ||
| - | ===== 3. Logging In with SSO ===== | + | T4 validates the token (signature, issuer, and expiry) and signs in the user whose '' |
| - | Once your provider is set up and a user is linked, log the user in by sending the OIDC ID token from your IdP in the T4 login request, in place of the password. T4 validates the token and signs in the matched user. | ||
| ===== Checklist ===== | ===== Checklist ===== | ||