Single sign-on and user provisioning

Table of Contents

Open the SSO & Provisioning tab. Only an administrator can use it.

The SSO & Provisioning page

Single sign-on (OIDC)

Taiwa works with OIDC identity providers. There are step-by-step guides for three of them:

Before you start

  • The redirect URI is the same for every organisation: https://api.taiwa.cx/v1/auth/sso/callback.
  • Ask Taiwa to verify the email domains that belong to your organisation. A sign-in from a domain that is not verified is refused.

What Taiwa needs from your identity provider

For a provider without a guide here, check these points:

  • An OIDC web application that uses the authorization code flow, with a client secret. Taiwa does not send PKCE.
  • The discovery document at the Issuer URL followed by /.well-known/openid-configuration. Its issuer must be the same as the Issuer URL.
  • The scopes openid, email and profile.
  • An ID token with the claims sub and email, and email_verified set to true. Microsoft Entra ID uses the claim xms_edov in place of email_verified.

Connect your identity provider

  1. In your identity provider, create an application for Taiwa with the redirect URI.
  2. In the portal, enter the Issuer URL. This is the OIDC discovery base, for example https://acme.okta.com.
  3. Enter the Client ID and the Client secret of that application.
  4. Select Save connection.

The single sign-on card

Important: a password manager can fill Client ID and Client secret with your own sign-in details. Check both fields before you save.

To change the connection later, edit the fields and select Update connection. Leave Client secret blank to keep the current secret.

How agents sign in

Agents select Sign in with SSO and enter the Organisation ID. This works in the admin portal, the extension and the Windows app.

Remove single sign-on

When you remove the connection, everyone signs in with a password again. Users that your identity provider created have no password. Send each of them an invite link from the Users tab.

Directory sync (SCIM 2.0)

With SCIM, your identity provider creates, updates and deactivates Taiwa users automatically.

  1. Under Directory sync (SCIM 2.0), copy the SCIM base URL.
  2. Select Generate token. Copy the bearer token at once. It is shown one time only.
  3. In your identity provider, enter the base URL and the token in its SCIM integration.

The directory sync card

To replace the token, select Rotate token, and enter the new token in your identity provider.

If you remove SCIM, your identity provider stops the sync. Existing users stay as they are. You then add and deactivate users by hand.

Freshdesk panel key

The same tab holds the key for the Taiwa app in Freshdesk. See Install the Taiwa app in Freshdesk.

Was this helpful?