**Advanced configuration: please rope in all pertinent IT resources before proceeding.
SSO Integrations
A Single Sign-On Integration can be achieved through the use of the SAML 2 authentication protocol. The process is relatively simple to set up if your institution supports authentication via a SAML 2 Identity Provider (IDP) and you've identified your IT personnel that govern such resources. To start the process please contact your customer success representative or reach out to support@suitable.co.
Metadata
The following are environments with respective Entity IDs for Suitable's test and production metadata:
Test
- Entity ID
- https://sandbox.suitable.co/saml
- Metadata
Production
- Entity ID
- https://app.suitable.co/saml
- Metadata
Once the metadata has been injected into your IDP, you will need to ensure the correct attributes are configured within the SAML Assertion. Below are required attributes:
- ePPN
- urn:oid:1.3.6.1.4.1.5923.1.1.1.6
- NameID
- Must exist in the Subject of the SAML Assertion. There is no required format but its value is recommended to mirror the above ePPN.
Encryption (Optional)
If your IDP requires encryption on assertions you must ensure one of the following encryption and key transport algorithm pairs are used:
Encryption Algorithm | Key Transport Algorithm |
---|---|
AES256-CBC | RSA-OAEP |
AES128-CBC | RSA-OAEP |
AES256-CBC | RSA-1.5 |
AES128-CBC | RSA-1.5 |
Initialization
To properly trigger SSO you will need to navigate to your institution's specific initialization url— depending on the environment. Please use the following url for the respective environment you are accessing.
Test
- https://sandbox.suitable.co/saml/institutions/<YOUR_INSTITUTION_ID>/login
Production
- https://app.suitable.co/saml/institutions/<YOUR_INSTITUTION_ID>/login
NOTE: <YOUR_INSTITUTION_ID> will be provided for the respective environment via your technical point of contact.
If you have additional questions, chat with us below or send us an email at support@suitable.co.
Comments
0 comments
Article is closed for comments.