Single Sign-on Setup Guide
Originality supports multiple authentication methods. If you wish to enable SSO using OpenID Connect, a configuration meeting will be required between your institution and the Originality team.
In this article:
- Supported identity providers
- Setup process (OIDC)
- Information required from the Institution
- Information provided by UNIwise
Supported identity providers
- Magic Link
- Microsoft Entra
- WAYF
- OpenID Connect (OIDC) v1.0-compliant Identity Providers
Setup process (OIDC)
To configure SSO in Originality using OIDC, a meeting must be scheduled with a representative from your institution who:
- Has administrative access to your Identity Provider (IdP) configuration, and
- Possesses technical knowledge of SSO setup.
Before the meeting, please securely provide the information listed in the section below.
During the meeting, UNIwise will:
- Share the configuration details needed to complete the setup on your IdP.
- Assist with testing the SSO connection.
- Enable your first administrator user once the setup is verified.
Information required from the Institution
Please provide the following details securely before the meeting:
- Email of initial Originality administrator (all administrators must have the same email domain - the part after @ must be the same)
- Client ID
- Client Secret (must be transmitted securely)
- Discovery Endpoint – e.g. `https://example.com/.well-known/openid-configuration
- Tenant ID (only required for Microsoft Entra)
The registered client must allow the following scopes:
- openid
- profile
Information provided by UNIwise
During the meeting, UNIwise will provide the Redirect URL, which must be added to your IdP configuration