Single Sign-On (SSO)
Configure authentication for access to the PCI Proxy dashboard with an identity provider.
Increase security and convenience for your team to login into the PCI Proxy dashboard by enabling SSO through your IdP (identity provider). It allows you to use one set of credentials to access multiple applications.
Activation
Single sign-on is available to all merchants on an Enterprise price plan. Please contact us to enable single sign-on for your team.
By default, all users are assigned with Read-only rights when logged in through SSO. Other user rights need to be assigned by an Administrator.
PCI Proxy supports currently the following Authentication Protocols/Provider:
- OpenID Connect (OIDC)
Setup & Activation
Please provide us with the following information through a secure channel to configure your account:
| Item | Example |
|---|---|
| OpenID Connect Discovery URL | https://login.microsoftonline.com/123e4567-e89b-12d3-a456-426614174000/v2.0/.well-known/openid-configuration |
| Client ID | a0ef2921-ac3c-4041-b424-74fe027fa26e |
| Client Secret | 3q1J0%F0c6?mcfhA?$}>j2*Z}uLCmsS5 |
| Email Domain(s) | example.com, example.org |
Callback URL
Configure the following callback URL in your identity provider:
https://login.pci-proxy.com/login/callback
Depending on the identity provider, this field may be called Redirect URI, Reply URL or Callback URL. The value must match the URL above exactly; otherwise, sign-in will fail.
Scopes
Configure the following scopes: openid email
PCI Proxy requires only the minimum information needed to sign users in. However, users must have an email address in your identity provider that matches your SSO domain.
Updated 2 days ago