OpenID Connect

Enable OpenID Connect Single Sign-On (SSO) to allow users to sign in to an Expert site from your sign-in portal.

In addition to the benefits of SSO, OpenID Connect provides advanced privacy configurations making it an ideal choice for an organization's customers to access applications that present a customer or consumer experience, such as an Expert site.

This solution is custom-configured for each client by MindTouch Professional Services. Elements and labels may differ from what is documented.

Terminology

Why Is OpenID Connect Recommended for Authentication?

Prerequisites

OpenID Connect sessions cannot occur behind existing VPN or IP-restrictions, if enabled for your Expert site.

Collect Information From Your Identity Provider

To configure a basic OpenID Connect integration, you will need the following information from your IdP:

Enable Group Synchronization (Optional)

  1. Create groups before enabling group synchronization
  2. Familiarize yourself with the behavior of group synchronization
  3. Provide the group claim name as it will appear in identity tokens or verbose user identity token received by the RP.

Next Steps

Contact your Customer Success Manager to discuss OpenID Connect integration services. Based on the complexity of your integration, you may need to only supply the IdP data described above, or you may work with them on more advanced integrations. The latter may require more involvement with your IdP maintainer or vendor, and additional information.