Learn how to configure Single Sign-On for a Vultr organization, connecting an OIDC identity provider through the Vultr Console for user authentication.
Single Sign-On (SSO) lets users in your organization sign in to Vultr through an external identity provider instead of a Vultr password. Vultr supports SSO through OpenID Connect (OIDC), and works with any OIDC-compliant identity provider.
Follow this guide to configure SSO for your organization using the Vultr Console.
In your identity provider's admin console, create a new OIDC application (sometimes called an app integration or app registration) for Vultr.
Set the application's sign-in redirect URI to your Vultr Console address followed by /openid/.
This must match exactly, including the trailing slash. A mismatch is the most common cause of login errors.
Assign the users or groups that should have access to the application.
Save the application, then note its Client ID, Client Secret, and issuer or discovery URL. You need these values in the next step.
Log in to the Vultr Console.
Click the organization name in the top navigation bar.
Click Manage Organization.
Click Federated Identity under Identity and Access Management in the left sidebar.
Under Single Sign-On, click Enable. Enable Single Sign-On panel opens on the right.
Enter the Provider URL (the issuer or discovery URL), the Client ID, and the Client Secret from your identity provider.
Click Enable SSO.
The SSO Status changes to Active, confirming the connection is configured.
Open a fresh or incognito browser window and go to the Vultr Console.
Click SSO in the login options.
Enter the email of a user assigned to the application, then click Continue. The Vultr Console redirects you to your identity provider for authentication.
After authentication, your identity provider redirects you back and signs you in to the Vultr Console.
Vultr verifies that the user your identity provider returns matches the email you entered. If your browser is already signed in as a different person, the login is rejected. Use an incognito window signed in as the intended user.
SSO signs in only users that already exist in Vultr. If the user hasn't been created yet, the login attempt fails with an Invalid email address error.
0 Comments
Be the first to comment and share your perspective with the community.