Single Sign-On (SSO)

Configure authentication for access to the PCI Proxy dashboard with an identity provider.

Increase security and convenience for your team to login into the PCI Proxy dashboard by enabling SSO through your IdP (identity provider). It allows you to use one set of credentials to access multiple applications.

Activation

📘

Single sign-on is available to all merchants on an Enterprise price plan. Please contact us to enable single sign-on for your team.

By default, all users are assigned with Read-only rights when logged in through SSO. Other user rights need to be assigned by an Administrator.

PCI Proxy supports currently the following Authentication Protocols/Provider:

  • OpenID Connect (OIDC)

Setup & Activation

Please provide us with the following information through a secure channel to configure your account:

ItemExample
OpenID Connect Discovery URLhttps://login.microsoftonline.com/123e4567-e89b-12d3-a456-426614174000/v2.0/.well-known/openid-configuration
Client IDa0ef2921-ac3c-4041-b424-74fe027fa26e
Client Secret3q1J0%F0c6?mcfhA?$}>j2*Z}uLCmsS5
Email Domain(s)example.com, example.org

Callback URL

Configure the following callback URL in your identity provider:

https://login.pci-proxy.com/login/callback

Depending on the identity provider, this field may be called Redirect URI, Reply URL or Callback URL. The value must match the URL above exactly; otherwise, sign-in will fail.

Scopes

Configure the following scopes: openid email

PCI Proxy requires only the minimum information needed to sign users in. However, users must have an email address in your identity provider that matches your SSO domain.



Did this page help you?