| Both sides previous revision Previous revision Next revision | Previous revision |
| developers:admin:sso [2026/09/29 12:47] – [3. Logging In with SSO] chad | developers:admin:sso [2026/09/29 14:12] (current) – [Common Provider Values] chad |
|---|
| | Subject claim | The claim that uniquely identifies a user. Use ''sub'' for most providers; ''oid'' for Entra ID. | | | Subject claim | The claim that uniquely identifies a user. Use ''sub'' for most providers; ''oid'' for Entra ID. | |
| |
| <bootnote important> | <bootnote> |
| The Issuer URL must match the ''iss'' claim in your tokens exactly, including any trailing slash. | The Issuer URL must match the ''iss'' claim in your tokens exactly, including any trailing slash. |
| </bootnote> | </bootnote> |
| |
| ==== Common Provider Values ==== | |
| |
| | **Provider** | **Issuer** | **Subject claim** | **JWKS URI** | | | **Provider** | **Issuer** | **Subject claim** | **JWKS URI** | |
| | Entra ID | ''https://login.microsoftonline.com/{tenantId}/v2.0'' | ''oid'' | ''https://login.microsoftonline.com/{tenantId}/discovery/v2.0/keys'' | | | Entra ID | ''%%https://login.microsoftonline.com/{tenantId}/v2.0%%'' | ''oid'' | ''%%https://login.microsoftonline.com/{tenantId}/discovery/v2.0/keys%%'' | |
| | Okta | ''https://{domain}/oauth2/default'' | ''sub'' | ''https://{domain}/oauth2/default/v1/keys'' | | | Okta | ''%%https://{domain}/oauth2/default%%'' | ''sub'' | ''%%https://{domain}/oauth2/default/v1/keys%%'' | |
| | Google | ''https://accounts.google.com'' | ''sub'' | ''https://www.googleapis.com/oauth2/v3/certs'' | | | Google | ''%%https://accounts.google.com%%'' | ''sub'' | ''%%https://www.googleapis.com/oauth2/v3/certs%%'' | |
| | AD FS | ''https://{adfs-host}/adfs'' | ''sub'' | ''https://{adfs-host}/adfs/discovery/keys'' | | | AD FS | ''%%https://{adfs-host}/adfs%%'' | ''sub'' | ''%%https://{adfs-host}/adfs/discovery/keys%%'' | |
| | Ping Identity | ''https://{env}.pingone.com/{envId}/as'' | ''sub'' | ''https://{env}.pingone.com/{envId}/as/jwks'' | | | Ping Identity | ''%%https://{env}.pingone.com/{envId}/as%%'' | ''sub'' | ''%%https://{env}.pingone.com/{envId}/as/jwks%%'' | |
| ===== 2. Link Each User to Their SSO Identity ===== | ===== 2. Link Each User to Their SSO Identity ===== |
| |
| | subject | The subject-claim value (''sub''/''oid'') for that user, as issued by your IdP. | | | subject | The subject-claim value (''sub''/''oid'') for that user, as issued by your IdP. | |
| |
| <bootnote important> | |
| ''subject'' is the stable, opaque identifier from your IdP (a GUID for Entra ID, a numeric string for Google) — not the user's email address, unless your IdP is configured to use email as the subject. | |
| </bootnote> | |
| |
| Set the link when onboarding, when creating a user, or on an existing user. | Set the link when onboarding, when creating a user, or on an existing user. |