This article explains how to set up single sign-on (SSO) between your identity provider (IdP) and Kaleidoscope using OpenID Connect (OIDC). Your IT administrator completes the steps in your IdP, then sends the details listed below to your Kaleidoscope CSM.
The names of menus and settings differ between identity providers. Use your IdP's documentation if a name below does not match.
Before you begin
Ask your Kaleidoscope CSM for the Redirect URI for your account. You need it in Step 1.
Step 1: Register Kaleidoscope as an application in your IdP
In your IdP administration console, create a new application (also called an app registration or client).
Select a web application type that uses the Authorization Code flow.
Enter the Redirect URI provided by your Kaleidoscope CSM.
Save the application.
Step 2: Copy the Client ID and Client Secret
Copy the Client ID that your IdP assigned to the application.
Create a Client Secret and copy it right away. Many IdPs only show the secret once.
If your Client Secret has an expiration date, note it. When the secret expires, create a new one and send it to your CSM so sign-in continues to work.
Step 3: Add API scopes
Make sure the application has permission to request these scopes:
openid
profile
email
If your organization requires administrator approval for these permissions, grant it.
Step 4: Copy the Authorization Endpoint
Find the Authorization Endpoint URL for your IdP. This is the URL where sign-in requests start. It is often shown on the application page, or in your IdP's OpenID configuration. It usually looks like this: https://idp.example.com/oauth2/authorize
Step 5: Assign a test user
Assign a test user to the application. The email address of the test user must match an existing account in the Kaleidoscope platform.
Send these details to your CSM
Client ID
Client Secret
Authorization Endpoint URL
API scopes enabled for the application
Your Kaleidoscope CSM will confirm when your SSO connection is ready to test.
