LogoLogo
HomeIntegrityControlSolutionsManagement Center
3.1.0 - Access
3.1.0 - Access
  • Introduction
  • The Service
    • Overview
    • About this release
      • Release notes
      • Breaking changes
    • Architecture
      • Modules
      • Folder structure
      • Startup
    • Getting started
    • Installation
      • Container
      • Linux
      • Windows
    • Operations
      • Configuration
      • Metrics
      • Health check
      • Logging
        • System logging
        • Event logging
      • SBOM & license material
  • Modules
    • External modules
    • Internal modules
      • SAMLModule
      • OIDC
        • OpenID Configuration endpoint
        • JWKS endpoint
        • Authorization endpoint
        • Token endpoint
          • Authorization code
          • Refresh token
        • User info endpoint
        • Introspection endpoint
        • End session endpoint
  • Configuration reference
    • Introduction
    • Terms and abbreviations
    • Property expansion
    • File inclusion
    • Secrets management
    • Examples
  • Authenticators
    • Introduction
    • Common configuration
    • Web Authenticator API
    • Flow control
      • Selector
      • AuthController
      • SSO Authenticator
      • Chain
      • Impersonate
      • Impersonate With Search
    • Credential validators
      • SITHS eID
        • With QR or "app-switch"
      • BankID
        • On another device
        • On mobile device
      • Freja e-ID
        • With user input
        • With QR or "app-switch"
      • Mobile ID
        • With QR or "app-switch"
      • Header based
        • Certificate
      • Pointsharp Net iD Access server
        • On another device
        • On same device
      • Integrated windows login, IWA
      • User name & password
      • User lookup
      • OTP validator
      • Passkey validator
      • Exposed metrics
      • Test
        • Static SAML
        • No operation
    • Protocol managers
      • SAML
        • SAML IDP
        • SAML SP
        • IDP Discovery Service
      • OIDC
        • Authorization Code Flow
        • Implicit Flow
        • OIDC Relying Party
    • UI
Powered by GitBook
On this page
  • Introduction
  • Configuration
  1. Authenticators
  2. Flow control

SSO Authenticator

PreviousAuthControllerNextChain

Introduction

The SSO authenticator is responsible for checking that a user is logged in and then redirect the user. It must NOT be placed in a chain. Used in a SSO scenario.

Configuration

Authenticator type: SSOAuthenticator

Common Authenticator configuration can be found .

Name
Description
Default
Mandatory

pipe_id

The pipe reference. The pipe is commonly used to extract data needed for the redirect.

N/A

redirect_url

The url to redirect to after the pipe is finished. Expandable.

N/A

identifier

Used to find the authenticated user. Expandable.

${session.identifier}

failure_location

The target location to where the user agent will be redirected when user is not authenticated.

N/A

{
    "id": "tsplus",
    "type": "SSOAuthenticator",
    "config": {
        "pipe_id": "tsplus",
        "identifier": "${session.identifier}",
        "redirect_url": "https://www.app.com/?server=${exports.server_name}&ticket=${exports.ticket}",
        "base_path": "/access/authn",
        "failure_location": "http://www.mycompany.com/errorpage"
    }
}

here