Skip to main content

OpenID Connect (OIDC) SSO Setup

Learn how to prepare your identity provider and what details to send Kaleidoscope to set up OpenID Connect (OIDC) single sign-on.

This article explains how to set up single sign-on (SSO) between your identity provider (IdP) and Kaleidoscope using OpenID Connect (OIDC). Your IT administrator completes the steps in your IdP, then sends the details listed below to your Kaleidoscope CSM.

The names of menus and settings differ between identity providers. Use your IdP's documentation if a name below does not match.

Before you begin

Ask your Kaleidoscope CSM for the Redirect URI for your account. You need it in Step 1.

Step 1: Register Kaleidoscope as an application in your IdP

  1. In your IdP administration console, create a new application (also called an app registration or client).

  2. Select a web application type that uses the Authorization Code flow.

  3. Enter the Redirect URI provided by your Kaleidoscope CSM.

  4. Save the application.

Step 2: Copy the Client ID and Client Secret

  1. Copy the Client ID that your IdP assigned to the application.

  2. Create a Client Secret and copy it right away. Many IdPs only show the secret once.

If your Client Secret has an expiration date, note it. When the secret expires, create a new one and send it to your CSM so sign-in continues to work.

Step 3: Add API scopes

Make sure the application has permission to request these scopes:

  • openid

  • profile

  • email

If your organization requires administrator approval for these permissions, grant it.

Step 4: Copy the Authorization Endpoint

Find the Authorization Endpoint URL for your IdP. This is the URL where sign-in requests start. It is often shown on the application page, or in your IdP's OpenID configuration. It usually looks like this: https://idp.example.com/oauth2/authorize

Step 5: Assign a test user

Assign a test user to the application. The email address of the test user must match an existing account in the Kaleidoscope platform.

Send these details to your CSM

  • Client ID

  • Client Secret

  • Authorization Endpoint URL

  • API scopes enabled for the application

Your Kaleidoscope CSM will confirm when your SSO connection is ready to test.

Did this answer your question?