| Both sides previous revision Previous revision Next revision | Previous revision |
| developers:admin:sso [2026/09/29 12:45] – chad | developers:admin:sso [2026/09/29 14:12] (current) – [Common Provider Values] chad |
|---|
| | Subject claim | The claim that uniquely identifies a user. Use ''sub'' for most providers; ''oid'' for Entra ID. | | | Subject claim | The claim that uniquely identifies a user. Use ''sub'' for most providers; ''oid'' for Entra ID. | |
| |
| <bootnote important> | <bootnote> |
| The Issuer URL must match the ''iss'' claim in your tokens exactly, including any trailing slash. | The Issuer URL must match the ''iss'' claim in your tokens exactly, including any trailing slash. |
| </bootnote> | </bootnote> |
| |
| ==== Common Provider Values ==== | |
| |
| | **Provider** | **Issuer** | **Subject claim** | **JWKS URI** | | | **Provider** | **Issuer** | **Subject claim** | **JWKS URI** | |
| | Entra ID | ''https://login.microsoftonline.com/{tenantId}/v2.0'' | ''oid'' | ''https://login.microsoftonline.com/{tenantId}/discovery/v2.0/keys'' | | | Entra ID | ''%%https://login.microsoftonline.com/{tenantId}/v2.0%%'' | ''oid'' | ''%%https://login.microsoftonline.com/{tenantId}/discovery/v2.0/keys%%'' | |
| | Okta | ''https://{domain}/oauth2/default'' | ''sub'' | ''https://{domain}/oauth2/default/v1/keys'' | | | Okta | ''%%https://{domain}/oauth2/default%%'' | ''sub'' | ''%%https://{domain}/oauth2/default/v1/keys%%'' | |
| | Google | ''https://accounts.google.com'' | ''sub'' | ''https://www.googleapis.com/oauth2/v3/certs'' | | | Google | ''%%https://accounts.google.com%%'' | ''sub'' | ''%%https://www.googleapis.com/oauth2/v3/certs%%'' | |
| | AD FS | ''https://{adfs-host}/adfs'' | ''sub'' | ''https://{adfs-host}/adfs/discovery/keys'' | | | AD FS | ''%%https://{adfs-host}/adfs%%'' | ''sub'' | ''%%https://{adfs-host}/adfs/discovery/keys%%'' | |
| | Ping Identity | ''https://{env}.pingone.com/{envId}/as'' | ''sub'' | ''https://{env}.pingone.com/{envId}/as/jwks'' | | | Ping Identity | ''%%https://{env}.pingone.com/{envId}/as%%'' | ''sub'' | ''%%https://{env}.pingone.com/{envId}/as/jwks%%'' | |
| ===== 2. Link Each User to Their SSO Identity ===== | ===== 2. Link Each User to Their SSO Identity ===== |
| |
| | subject | The subject-claim value (''sub''/''oid'') for that user, as issued by your IdP. | | | subject | The subject-claim value (''sub''/''oid'') for that user, as issued by your IdP. | |
| |
| <bootnote important> | |
| ''subject'' is the stable, opaque identifier from your IdP (a GUID for Entra ID, a numeric string for Google) — not the user's email address, unless your IdP is configured to use email as the subject. | |
| </bootnote> | |
| |
| Set the link when onboarding, when creating a user, or on an existing user. | Set the link when onboarding, when creating a user, or on an existing user. |
| ===== 3. Logging In with SSO ===== | ===== 3. Logging In with SSO ===== |
| |
| Log the user in with the standard [[developers:apiv2:connecting|LoginRequest]], but instead of ''username''/''password'' set the OIDC token from your IdP. Use ''id_token'' (preferred), or ''access_token'' if your flow only issues an access token. ''app_name'' and ''app_license'' are still required. | Log the user in with the standard [[developers:apiv2:connecting|LoginRequest]], but instead of ''username''/''password'' set your IdP's OIDC ID token in the ''id_token'' field. ''app_name'' and ''app_license'' are still required. |
| |
| <code> | <code> |