{"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"ssodirect","__idx":0},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["ssoDirect"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Control identity and access with the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["ssoDirect"]}," configuration option."," ","Allows more customization than ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"/docs/realm/config/access/sso"},"children":["sso"]},"."]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"warning","name":"Enterprise+"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Available with Enterprise+."," ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"https://redocly.com/contact-us"},"children":["Contact us"]}," to upgrade or learn more."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"options","__idx":1},"children":["Options"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Option"},"children":["Option"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Type"},"children":["Type"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Description"},"children":["Description"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["ssoDirect"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Map[string, ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"#idp-object"},"children":["IDP objects"]},"]"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Map of IDPs which can be ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"#oidc-object"},"children":["OIDC object"]},", or ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"#saml2-object"},"children":["SAML2 object"]}]}]}]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"idp-object","__idx":2},"children":["IDP object"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["An IDP object can be one of the following types:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["OpenID Connect (OIDC) object (see ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"#oidc-object"},"children":["OIDC object"]},")"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Security Assertion Markup Language (SAML) object (see ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"#saml2-object"},"children":["SAML2 object"]},")"]}]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Option"},"children":["Option"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Type"},"children":["Type"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Description"},"children":["Description"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["type"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["string"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Possible values: ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["OIDC"]},", ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["SAML2"]},"."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["title"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["string"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Optional title that can be used on the login page when multiple IDPs are configured."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"em","attributes":{},"children":["additionalProperties"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["any"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Depends on the type value."," ","See ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"#oidc-object"},"children":["OIDC object"]}," and ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"#saml2-object"},"children":["SAML2 object"]}," for details."]}]}]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"oidc-object","__idx":3},"children":["OIDC object"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Option"},"children":["Option"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Type"},"children":["Type"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Description"},"children":["Description"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["type"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["string"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["REQUIRED."]}," ","Specifies the type of identity provider."," ","Possible value: ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["OIDC"]},"."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["configurationUrl"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["string"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["REQUIRED if ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["configuration"]}," property is missing."]}," ","OpenID configuration URL for your identity provider."," ","This is typically in the format ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://{identity-provider-hostname}/.well-known/openid-configuration"]},"."," ","Select the appropriate scopes to set your user attributes during authentication to authorize access."," ","Mutually exclusive with ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["configuration"]},"."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["configuration"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"Link","attributes":{"href":"#oidc-metadata-object"},"children":["OIDC Metadata object"]}]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["REQUIRED if ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["configurationUrl"]}," property is missing."]}," ","OpenID configuration."," ","You can copy-paste the content of the configuration endpoint to ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["configuration"]}," property if your OpenID configuration URL is protected by some header-based authorization."," ","Mutually exclusive with ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["configurationUrl"]},"."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["clientId"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["string"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["REQUIRED."]}," ","Unique ID to identify Redocly with your IdP authorization server."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["clientSecret"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["string"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["REQUIRED if ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["pkce"]}," is ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["false"]}]}," ","Secret password that only Redocly and your IdP authorization server know."," ","Keep secrets out of a repository and use environment variable references like this example: ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["{{process.env.MAIN_CLIENT_SECRET | \"test-secret\" }}"]},"."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["pkce"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["boolean"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Use ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"https://oauth.net/2/pkce/"},"children":["PKCE"]}," for the authorization code flow."," ","If ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["true"]},", the ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["clientSecret"]}," is not required."," ","Default: ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["false"]},"."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["scopes"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["[string]"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["REQUIRED."]}," ","List of scopes."," ","Scopes are used during authentication to authorize access to a person's details, like name and picture."," ","The scopes must include ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["openid"]}," and ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["email"]},"."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["teamsClaimName"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["string"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Claim name to use for role-based access control."," ","Default: ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://redocly.com/sso/teams"]},"."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["teamsClaimMap"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["object"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Map of team claim values to team names."," ","Useful when the IdP team attribute values are not the same as the team names."," ","Default: ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["{}"]},"."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["defaultTeams"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["[string]"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["List of teams to assign to all users by default for this identity provider."," ","Default: ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["[]"]},"."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["tokenExpirationTime"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["integer"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Overrides the time until the token expires in seconds."," ","If not provided, the token expiration is used from the identity provider."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["authorizationRequestCustomParams"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["string"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Parameters added to the authorization URL."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["tokenRequestCustomParams"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["string"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Parameters added to the token URL."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["audience"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["[string]"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["An array of allowed OIDC audience values."," ","Matched against ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["aud"]}," claim in OIDC ID token."," ","If not specified or is an empty array, all of the audiences are allowed."]}]}]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"oidc-metadata-object","__idx":4},"children":["OIDC metadata object"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The OIDC metadata object as documented in ",{"$$mdtype":"Tag","name":"Link","attributes":{"href":"https://openid.net/specs/openid-connect-discovery-1_0.html#ProviderMetadata"},"children":["OIDC specification"]},"."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"saml2-object","__idx":5},"children":["SAML2 object"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Option"},"children":["Option"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Type"},"children":["Type"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Description"},"children":["Description"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["type"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["string"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["REQUIRED."]}," ","Specifies the type of identity provider."," ","Possible value: ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["SAML2"]},"."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["issuerId"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["string"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["REQUIRED."]}," ","Unique identifier of the identity provider."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["entityId"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["string"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Unique identifier of the project SP."," ","Default value when hosting on Redocly: ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://api.redocly.com/sso/project/<project-name>"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["ssoUrl"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["string"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["REQUIRED."]}," ","URL to redirect users to log in."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["x509PublicCert"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["string"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["REQUIRED."]}," ","Public certificate in x.509 format for the identity provider."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["teamsAttributeName"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["string"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Attribute name to use for role-based access control."," ","Default: ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://redocly.com/sso/teams"]},"."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["teamsAttributeMap"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["object"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Map of team attribute values to team names."," ","Useful when the IdP team attribute values are not the same as the team names."," ","Default: ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["{}"]},"."]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["defaultTeams"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["[string]"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":["List of teams to assign to all users by default for this identity provider."," ","Default: ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["[]"]},"."]}]}]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"examples","__idx":6},"children":["Examples"]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"oidc-example","__idx":7},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["OIDC"]}," example"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["In your OIDC identity provider settings, set the appropriate URL for \"Allowed Callback URLs\":"]},{"$$mdtype":"Tag","name":"div","attributes":{"className":"md-table-wrapper"},"children":[{"$$mdtype":"Tag","name":"table","attributes":{"className":"md"},"children":[{"$$mdtype":"Tag","name":"thead","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Environment"},"children":["Environment"]},{"$$mdtype":"Tag","name":"th","attributes":{"data-label":"Allowed callback URL"},"children":["Allowed callback URL"]}]}]},{"$$mdtype":"Tag","name":"tbody","attributes":{},"children":[{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Local development"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["http://localhost:4000/_auth/oidc"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Preview"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://previewauth--{YOUR_PROJECT_NAME}.redocly.app/_auth/oidc"]}]}]},{"$$mdtype":"Tag","name":"tr","attributes":{},"children":[{"$$mdtype":"Tag","name":"td","attributes":{},"children":["Production"]},{"$$mdtype":"Tag","name":"td","attributes":{},"children":[{"$$mdtype":"Tag","name":"code","attributes":{},"children":["https://{YOUR_CUSTOM_DOMAIN}/_auth/oidc"]}]}]}]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Replace ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["{YOUR_PROJECT_NAME}"]}," and ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["{YOUR_CUSTOM_DOMAIN}"]}," with actual values."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The following is an example configuration."]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"yaml","header":{"controls":{"copy":{}}},"source":"ssoDirect:\n  main:\n    type: OIDC\n    # well-known URL from your IdP\n    configurationUrl: https://accounts.google.com/.well-known/openid-configuration\n    # Client or application ID\n    clientId: sO3vEhnjmjYci16Z2cRJUMO64NDEy0mD\n    # Client secret\n    clientSecret: '{{process.env.MAIN_CLIENT_SECRET | \"test-secret\"}}'\n    # Name of the claim with teams array received from IdP in ID token\n    teamsClaimName: https://redocly.com/sso/teams\n    # List of scopes. By default only openid scope is used\n    scopes:\n      - openid\n      - email\n      - name\n","lang":"yaml"},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"saml2-example","__idx":8},"children":["SAML2 example"]},{"$$mdtype":"Tag","name":"CodeBlock","attributes":{"data-language":"yaml","header":{"controls":{"copy":{}}},"source":"ssoDirect:\n  demoSaml:\n    type: SAML2\n    ssoUrl: https://dev-7ybkoxrd.us.auth0.com/samlp/cAByzjnpSdYvgcKmAr6nZPvPvpe4Oa4N\n    issuerId: urn:dev-7ybkoxrd.us.auth0.com\n    x509PublicCert: MIIDDTCCAfWgAwIBAgIJL/BU7qYCB8DYMA0GCSqGSIb3DQEBCwUAMCQxIjAgBgNVBAMTGWRldi03eWJrb3hyZC51cy5hdXRoMC5jb20wHhcNMjIwODEwMDg1MTA1WhcNMzYwNDE4MDg1MTA1WjAkMSIwIAYDVQQDExlkZXYtN3lia294cmQudXMuYXV0aDAuY29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA3Tr7a4BVupU/VrR8dxBkRMQkRTfysTPazTn2zJAPpWs/cdj6+/be99d1rQfUAXTSTUNf7P/AQ3dZ1GN1VQxi54qELaXOtzPHrNHLTJb+jotqUAesAI2nPno/hrOx4OeLIFzVucYpE3CYAui8YVedUS/QUITgVoP2+PIy5gXrfXg6Ap8QFNH6IdHqpond2ebTFL8KGZLjn8t7+FwEzrWDeUtSMJdauiQzLum5XfYT5+FaLnrOGfZgJINnrUfx9867ITo2Tq9j6ydr5z/gI9RM1S9pkuxO0SDbbbIWkS1hY6H/pL0y7TZB5edysVWXu0m9CMQMIMnI6HIkQoV6m3hV2wIDAQABo0IwQDAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQWBBTBd6jzJ05JwBk4TfCEPkBjT/iVwTAOBgNVHQ8BAf8EBAMCAoQwDQYJKoZIhvcNAQELBQADggEBAKLBX+twRxbFw5kSNfM5I0dljkZN2X5ypzApkTbDs1Ios5vY1WmdnqugtyA9BAKAq+EW4fg1HpuI+80hMMQ+Tkm2dDcepGwSjyHFouTarvDeOdgk5WHbKTceeItuFCZutHpzlPFjxgrrNszGzfbG6ttw2nWCBkJmftWLFYyuAH/hjcgQ2sq/j0+5p57jxYsoVL5pyDjubHcWxHw+4hM/xAAsq6ONVA57wesvYPUFZJ1CejKljZ1K5Md+EnjJQWcCBD8nRY4OTVxl1pa0UyCLSKGVR0F2LhPvb6HUf2syeJxXXtVWlzHTlzGDZQiHF3DDZrgu2mNdFwBiU1e1nM1hnQw=\n    teamsAttributeName: http://schemas.auth0.com/https://redocly.com/sso/teams\n","lang":"yaml"},"children":[]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"resources","__idx":9},"children":["Resources"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":[{"$$mdtype":"Tag","name":"Link","attributes":{"href":"/docs/realm/config/access/rbac"},"children":["RBAC configuration reference"]}]}," - Complete configuration options for role-based access control integration with direct SSO authentication"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":[{"$$mdtype":"Tag","name":"Link","attributes":{"href":"/docs/realm/access/rbac"},"children":["Role-based access control"]}]}," - Understand RBAC fundamentals and how they work with direct SSO for comprehensive access management"]}]}]},"frontmatter":{"products":["Redoc","Revel","Reef","Realm"],"plans":["Enterprise+"],"excludeFromSearch":true},"tagList":["admonition","table"],"title":"ssoDirect","lastModified":"2026-10-01T23:00:57.000Z"}