Docs

Type at least 2 letters.

    SSO

    Set up single sign-on for the tenant with an OIDC identity provider and verify your company's email domains.

    Updated View as Markdown

    With SSO, members sign in to Advisor through your company's identity provider (IdP). Setup has two parts: registering the IdP through OIDC and verifying the email domains that will use it.

    Before you start

    • You need the tenants.sso.manage permission. The Tenant Admin role has it.
    • You need access to your IdP to create an OIDC application.
    • To verify a domain, you need access to publish a TXT record in the domain's DNS.

    1. Register the identity provider

    1. Go to Administração (Administration) > Acesso (Access) > SSO.

    2. Under Provedor de identidade (Identity provider), copy the Redirect URI and the Post-logout redirect URI.

    3. In your IdP, create an OIDC application and paste the two URIs you copied.

    4. Configure the IdP to send the email claim in the ID token.

    5. Back in Advisor, fill in the fields:

      Field What to enter
      Issuer (URL) Your IdP's issuer address. It must start with https.
      Client ID The ID of the application created in the IdP.
      Client secret The secret of the application created in the IdP.
    6. Save the configuration.

    2. Verify an email domain

    SSO applies to emails from verified domains.

    1. Under Domínios de e-mail (Email domains), type the domain and select Reivindicar (Claim).

    2. In the domain's DNS, publish a TXT record:

      Name Value
      _advisor-verify.<domain> advisor-domain-verification=<token>

      Advisor shows the token on screen.

    3. Once the record is published, select Verificar (Verify).

    Domain states

    State What it means
    Reivindicado (Claimed) The domain was registered, but the TXT record has not been confirmed yet.
    Verificado (Verified) SSO is available for the domain's emails. Password sign-in still works.
    Obrigatório (Required) Emails from this domain can no longer sign in with a password. Sign-in is available only through SSO.

    Session

    A session opened through the company SSO lasts 8 hours. After that, the person signs in again through the IdP.

    Turn off SSO

    When you select Desligar SSO (Turn off SSO), all domains go back to password sign-in and the IdP configuration is erased. To use SSO again, register the provider again.

    See also