Integrations
Single sign-on
Single sign-on lets your people reach Kontier with the account they already have, rather than another password.
What SSO decides
SSO decides how somebody proves who they are. It does not decide what they can do once inside; that is still their role.
So connecting an identity provider does not grant anybody access. People still have to exist in your organization with a role, and somebody who signs in successfully but holds no role can do nothing.
Before you switch it on
Two habits worth keeping:
- Keep one administrator who can sign in without SSO. A misconfigured provider otherwise locks everybody out, including the person who could fix it.
- Test with a real account first. SSO configuration tends to be right or entirely wrong, and the failure is not subtle.
Reference
| Topic | When you need it |
|---|---|
| Team and roles | What somebody can do once signed in |
| Security | Two-factor and session policy |
| API keys | Access for systems, which SSO does not cover |
Last modified on