Ovyero
Documentation

Set up single sign-on

Enterprise organizations configure single sign-on themselves in the dashboard, with OIDC or SAML. An organization uses one protocol at a time. Changes need the organization owner and a sign-in from the last 10 minutes.

OIDC

  1. In your identity provider, create an application and register this redirect URI: https://ovyero.visnryentertainment.com/api/v1/auth/sso/callback
  2. In the dashboard open Settings → Security & access and enter the Issuer URL (must be https://), the Client ID, the Client Secret and your allowed email domains. Save.
  3. Run Test connection, then Enable. Saving alone never turns SSO on.

SAML

  1. Give your identity provider the service-provider values shown on the SAML card in Settings: the ACS URL https://ovyero.visnryentertainment.com/api/v1/auth/saml/acs and the metadata URL https://ovyero.visnryentertainment.com/api/v1/auth/saml/metadata?tenant=<your organization id>.
  2. Enter your provider’s entity ID, sign-in URL (must be https://) and signing certificate (the PEM block that starts -----BEGIN CERTIFICATE-----), plus at least one allowed email domain. Save.
  3. Run a test sign-in. SAML can be enabled only after a real signed assertion from your provider has been verified.
  4. Enable.

Require single sign-on

The owner can require SSO for the organization. Set up and test your provider first. While the requirement is on, SSO cannot be disabled: turn off “Require single sign-on” before disabling the provider, otherwise everyone would be locked out.

Troubleshooting

More: Troubleshooting.

TroubleshootingContactTrust