Skip to main content

SSO providers

Where: Settings → SSO providers

Settings → SSO providers configures OpenID Connect single sign-on: “Admin-audience providers sign in seller-side staff; storefront-audience providers sign in a buying company’s users (JIT-provisioned).”

Figure: Settings → SSO providers — OIDC for staff and buyer organizations

Settings → SSO providers — OIDC for staff and buyer organizations

  1. Press “New provider”.
  2. Fill in: Name, Audience (admin = your staff; storefront = a buying company’s users, in which case also pick the Customer), then the OIDC details from the identity provider: Issuer, Authorization endpoint, Token endpoint, JWKS URI, Client ID, Client secret (“blank = keep” on edit), Scopes (default “openid email profile”).
  3. Use the provider row’s test login link to verify before rolling it out.
note

This screen is OIDC-only. SAML is supported by the platform but is configured by your operator/IT through the API, not through this page — configured SAML providers do appear in the table with their metadata link.