Single Sign-On (SSO) with OpenID Connect (OIDC)

Knowledge Base
Print

Single Sign-On (SSO) with OpenID Connect (OIDC)

In this article

Enterprise plans in Kanban Zone will have access to Single Sign-On.

OpenID Connect (OIDC) is an open authentication protocol that works on top of the OAuth 2.0 framework. OIDC allows Kanban Zone members to use single sign-on (SSO) to access Kanban Zone using an OpenID Identity Provider (IdP) to authenticate their identities.

Organizations within Kanban Zone can choose to enforce SSO for all members of their Kanban Zone organization or configure select members to bypass and login with their Kanban Zone email address.

What you will need

  1. An Enterprise Plan in Kanban Zone
  2. An OpenID Connect (OIDC) compatible Identity Provider (IdP)
  3. Your IdP Issuer Url/Base Url
  4. Your IdP Application Client ID
  5. The Kanban Zone redirect URI – https://kanbanzone.io/login/sso/complete
    1. This is used within your IdP application setup when prompted for a redirect URI
  6. Access to the Kanban Zone SSO Organization Configuration
    1. The Organization Owner of Kanban Zone will have access
    2. Any Kanban Zone member with Security Permissions will have access, for more information on permissions, see our manage members article

IdP Setup and Configuration

  1. Setup your Implicit Grant and Hybrid Flows (Grant Type) to:
    1. Allow Hybrid Flow
    2. Allow ID Tokens with Implicit Grant Types

Kanban Zone Setup and Configuration

  1. Navigate to the Organization Settings by clicking your avatar in the top/right and then clicking Organization Settings from the menu
  2. From the left navigation, choose Single Sign-On (SSO)
    screenshot of the single sign on menu
  3. Enter your Issurer URL provided by your IdP
  4. Enter your Kanban Zone application client ID provided by your IdP
  5. The test connection button can be used to verify your Issurer URL.
  6. Choose your login behavior overrides
    1. A login behavior override allows select members of your Kanban Zone organization to use their Kanban Zone credentials to gain access to Kanban Zone and bypass using their SSO credentials
    2. Members who are added to your login behavior override lists will show a ‘Bypass’ badge in your organization member management screen. See Manage Members Organization – Badges section for more information
  7. Save your changes using the SAVE button at the top right of your configuration screen

A member of Kanban Zone can ONLY use SSO credentials when they belong to a single organization. If the Kanban Zone member belongs to 1+ organizations, they will ONLY be allowed to access Kanban Zone with their Kanban Zone email and password.

If a multi-organizational Kanban Zone member is invited to your SSO organization, they will not have access to your organization unless you add them to your login overrides to bypass using SSO.

Once bypassed, this member can login with their Kanban Zone credentials and be granted access to your organization.

This approach is often used for vendors or 3rd party members who belong to multiple Kanban Zone organizations OR do not exist in your IDP.

8. Once you have configured your SSO, it needs to be enabled.

screenshot of enabling the SSO

Login with SSO

If SSO is enabled for your organization in Kanban Zone, members can now login using their Kanban Zone email and SSO credentials.

  1. Navigate to https://kanbanzone.io/login and choose Login with SSO or navigate directly to https://kanbanzone.io/login/sso
    screenshot of the login with SSO button
    logging in with SSO
  2. Enter your email address
    1. Your IdP email address is the same as your Kanban Zone email address from your confirmed signup
    2. Your IdP will then prompt you for your password
Was this article helpful?
How can we improve this article?
Please submit the reason for your vote so that we can improve the article.