Open the SSO & Provisioning tab. Only an administrator can use it.
Single sign-on (OIDC)
Taiwa works with OIDC identity providers. There are step-by-step guides for three of them:
- Set up single sign-on with Microsoft Entra ID
- Set up single sign-on with Okta
- Set up single sign-on with Google Workspace
Before you start
- The redirect URI is the same for every organisation:
https://api.taiwa.cx/v1/auth/sso/callback. - Ask Taiwa to verify the email domains that belong to your organisation. A sign-in from a domain that is not verified is refused.
What Taiwa needs from your identity provider
For a provider without a guide here, check these points:
- An OIDC web application that uses the authorization code flow, with a client secret. Taiwa does not send PKCE.
- The discovery document at the Issuer URL followed by
/.well-known/openid-configuration. Itsissuermust be the same as the Issuer URL. - The scopes
openid,emailandprofile. - An ID token with the claims
subandemail, andemail_verifiedset totrue. Microsoft Entra ID uses the claimxms_edovin place ofemail_verified.
Connect your identity provider
- In your identity provider, create an application for Taiwa with the redirect URI.
- In the portal, enter the Issuer URL. This is the OIDC discovery base, for example
https://acme.okta.com. - Enter the Client ID and the Client secret of that application.
- Select Save connection.
Important: a password manager can fill Client ID and Client secret with your own sign-in details. Check both fields before you save.
To change the connection later, edit the fields and select Update connection. Leave Client secret blank to keep the current secret.
How agents sign in
Agents select Sign in with SSO and enter the Organisation ID. This works in the admin portal, the extension and the Windows app.
Remove single sign-on
When you remove the connection, everyone signs in with a password again. Users that your identity provider created have no password. Send each of them an invite link from the Users tab.
Directory sync (SCIM 2.0)
With SCIM, your identity provider creates, updates and deactivates Taiwa users automatically.
- Under Directory sync (SCIM 2.0), copy the SCIM base URL.
- Select Generate token. Copy the bearer token at once. It is shown one time only.
- In your identity provider, enter the base URL and the token in its SCIM integration.
To replace the token, select Rotate token, and enter the new token in your identity provider.
If you remove SCIM, your identity provider stops the sync. Existing users stay as they are. You then add and deactivate users by hand.
Freshdesk panel key
The same tab holds the key for the Taiwa app in Freshdesk. See Install the Taiwa app in Freshdesk.