{"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"identity-providers","__idx":0},"children":["Identity providers"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Organizations can set up multiple identity providers (IdPs) for storing and authenticating the identities that their users use to log in to their systems and applications."]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"info"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Redocly currently only supports the OpenID Connect (OIDC) identity provider for advanced functionality including RBAC and API gateway proxy integrations."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"add-a-new-identity-provider-idp","__idx":1},"children":["Add a new identity provider (IdP)"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["This section describes how organization owners can add a new identity provider in Redocly ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"https://app.redocly.com"},"children":["Workflows"]},"."]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Log in to your organization in ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"https://app.redocly.com/"},"children":["Workflows"]}," and select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Settings"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["From the left, select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Identity providers"]},". The ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Identity providers"]}," page displays."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["New Provider"]}," to add a new identity provider. You can choose from ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"#configure-openid-connect"},"children":["OpenID Connect"]}," or ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"#configure-saml2"},"children":["SAML2"]},"."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"configure-openid-connect","__idx":2},"children":["Configure OpenID Connect"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["On the OpenID Connect dialog, enter the following information:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Name"]},": Enter a name to identify the identity provider in Workflows. This name is displayed in the Access control settings for Reference docs and Developer portal."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Default organization role"]},": From the dropdown, select the default role that will be automatically assigned to people using this identity provider. This is essential for just-in-time provisioning."," ","For more information on roles and permissions associated with roles, refer to the ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"/docs-legacy/people/roles-permissions"},"children":["Roles and permissions"]}," topic."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Team assigned by default"]},": While adding an IdP, you can assign people to an existing team by default, based on some of the people's attributes (claims). See the ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"#map-teams-to-identity-providers"},"children":["Map teams to identity providers"]}," section."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Configuration URL (.well-known)"]},": The OpenID configuration URL for your identity provider. This is typically in the format ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://{identity-provider-hostname}/.well-known/openid-configuration"]},". When you enter the Configuration URL, the supported OIDC scopes display."," ","Select the appropriate scopes to set your user attributes during authentication to authorize access. Alternatively you can copy-paste the content of the configuration endpoint if your OpenID configuration URL is protected by some header-based authorization."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Scopes"]},": Select the scopes you want to associate with the IdP. Scopes are used during authentication to authorize access to a person's details, like name and picture."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Client ID"]},": Unique ID to identify Redocly with your IdP authorization server."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Client Secret"]},": Secret password that only Redocly and your IdP authorization server know."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["RBAC roles claim name"]},": If you are using Role Based Access Control (RBAC), enter the roles claim name to reuse the identity provider across multiple roles."," ",{"$$mdtype":"Tag","name":"Image","attributes":{"src":"/content-assets/add-oidc-details-236b2852addd1abd.png","alt":"Add OIDC details","title":"#display=block;margin=auto;width=500px;"},"children":[]}]}]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"info"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Organization owners can find out these details from their identity provider. For more information, see the Identity providers and OIDC configuration section."]}]},{"$$mdtype":"Tag","name":"details","attributes":{},"children":[{"$$mdtype":"Tag","name":"summary","attributes":{},"children":["Identity providers and OIDC configuration"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["This list shows the configuration URLs and associated documentation for a few popular identity providers."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Google Cloud Platform (GCP)"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Config URL: ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://accounts.google.com/.well-known/openid-configuration"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Docs: ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"https://developers.google.com/identity/protocols/oauth2/openid-connect#discovery"},"children":["Google OIDC docs"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Okta"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Config URL: ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://${yourOktaDomain}/oauth2/default/.well-known/openid-configuration"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Docs: ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"https://developer.okta.com/docs/concepts/auth-servers/"},"children":["Okta Developer docs"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Auth0"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Config URL: ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://YOUR_AUTH0_DOMAIN/.well-known/openid-configuration"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Docs: ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"https://auth0.com/docs/connections/enterprise/oidc"},"children":["Auth0 documentation"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["AWS Cognito"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Config URL: ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://cognito-idp.{region}.amazonaws.com/{userPoolId}/.well-known/openid-configuration"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Docs: ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"https://docs.aws.amazon.com/cognito/latest/developerguide/cognito-user-pools-oidc-idp.html"},"children":["AWS Cognito docs"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Microsoft Active Directory"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Config URL: ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://login.microsoftonline.com/common/v2.0/.well-known/openid-configuration"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Docs: ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"https://docs.microsoft.com/en-us/azure/active-directory/develop/v2-protocols-oidc"},"children":["Microsoft OIDC docs"]}]}]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Save"]}," to save your changes."]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"configure-saml2","__idx":3},"children":["Configure SAML2"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["On the SAML2 dialog, enter the following information:",{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Name"]},": Enter a name to identify the identity provider. This name is displayed in the Access control settings for Reference docs and Developer portal."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Default organization role"]},": From the dropdown, select the default role that will be automatically assigned to people using this identity provider. This is essential for just-in-time provisioning."," ","For more information on roles and permissions associated with roles, refer to the ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"/docs-legacy/people/roles-permissions"},"children":["Roles and permissions"]}," topic."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Team assigned by default"]},": While adding an IdP, you can assign people to an existing team by default, based on some of the people's attributes (claims). See the ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"#map-teams-to-identity-providers"},"children":["Map teams to identity providers"]}," section."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Single Sign On URL"]}," - Enter the URL required for redirecting users for logging in."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Issuer ID"]}," - Enter the unique identifier of the identity provider."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["x509 public certificate"]},": Paste the x.509 public certificate for the IdP."," ",{"$$mdtype":"Tag","name":"Image","attributes":{"src":"/content-assets/add-saml2-details-50af19cdee7f70b0.png","alt":"Add SAML2 details","title":"#display=block;margin=auto;width=500px;"},"children":[]}]}]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Use values provided in the dialog to configure a new SAML application in your IdP:",{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Use the value provided in the \"Single Sign Url (ACS)\" field to configure \"Single Sign On URL\", (can be called \"ACS URL\", \"Assertion consumer service URL\", depending on your IdP)"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Use the value provided in \"Entity ID\" to configure \"Audience URI\" (can also be called \"SP Entity ID\", depending on your IdP)"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Ensure that \"Name ID Format\" is set to \"EmailAddress\"."]}]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Save"]}," to apply your changes."]}]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"info","name":"About RBAC claim names"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Redocly only supports limited claim mapping. For both OIDC and SAML, customers can configure their IdP access token or ID token to contain a ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://redocly.com/sso/organization-role"]}," claim or attribute with an organization role value (OWNER, MEMBER, PARTICIPANT). This value will override the ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Default organization role"]}," configured above."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"map-teams-to-identity-providers","__idx":4},"children":["Map teams to identity providers"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["If you have set up ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"/docs-legacy/teams"},"children":["teams"]}," in your organization, you can map teams to the relevant IdPs so that organization administrators (people with ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Owner"]}," role) can automatically map the people in their organization to different teams based on some of their attributes (claims)."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["For example, you can set up mapping rules for everyone who has an organization unit claim to automatically join an ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Admins"]}," team. The ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Admins"]}," team can be set to access every project, so effectively, people who log in with the organization unit claim can access every project in Workflows."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"manage-access-control","__idx":5},"children":["Manage access control"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Once you have set up your identity providers, you can manage access control to your:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"Link","attributes":{"href":"/docs-legacy/api-registry/settings/manage-access"},"children":["API versions and docs"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"Link","attributes":{"href":"/docs-legacy/developer-portal/settings/manage-access"},"children":["Portals"]}]}]}]},"frontmatter":{"seo":{"title":"Configuring multiple identity providers (IdPs)"},"excludeFromSearch":true},"tagList":["admonition","html"],"title":"Configuring multiple identity providers (IdPs)","lastModified":"2025-05-28T16:01:32.000Z"}