Connect Xcellerate AIG to your identity provider and your staff sign in to the AIG admin console with their company account. Your directory decides who gets which role. Add SCIM and new starters get an account automatically, while leavers lose access as soon as you deactivate them.
TL;DR
- AIG supports single sign-on over OpenID Connect (OIDC), with presets for Microsoft Entra ID, Okta, Google Workspace, Keycloak and Auth0, plus a generic OIDC option.
- Roles come from group or app-role mappings and are applied at every sign-in.
- Optional SCIM 2.0 provisioning creates, updates and deactivates accounts from your directory.
Before you start
- You have the Admin role in AIG.
- You have an OIDC app registration (type Web) at your identity provider, with a client ID and a client secret.
- You know the Redirect URI that AIG shows. It has the form
https://<your-gateway>/sso/callbackand is built from the Base URL in General settings, so set that correctly first. - If you want to require single sign-on, you need at least one active user you can mark as a break-glass account.
Set up single sign-on
1. Register an app at your identity provider
Create a Web app registration and add the Redirect URI exactly as AIG shows it. Note the client ID, the client secret and the issuer URL. Per provider:
- Microsoft Entra ID: issuer
https://login.microsoftonline.com/<tenant-id>/v2.0, scopesemail profile, groups claimroles. Use app roles: Entra's groups claim carries object IDs, not names. - Okta: issuer
https://<your-domain>.okta.com/oauth2/default, scopesemail profile groups. Add a "groups" claim to the authorization server. - Google Workspace: issuer
https://accounts.google.com. Google sends no groups, so use the default role and assign roles in AIG. - Keycloak: issuer
https://<host>/realms/<realm>. Add a Group Membership mapper with full path switched off. - Auth0: issuer
https://<your-tenant>.eu.auth0.com/, trailing slash included. Add a namespaced roles claim with a Login action. - Any other provider with a discovery document: choose Generic OpenID Connect.
2. Enter the connection in AIG
Go to Administration → All screens → Single sign-on and click Set up single sign-on. Pick your Provider; the preset fills in Scopes and Groups claim. Paste the Issuer, Client ID and Client secret, then save. Sign-in does not change yet.
3. Test the connection
Click Test connection. AIG fetches the discovery document of the saved issuer. It does not check the client secret. The login page now shows an SSO button: sign in once yourself in a private window to confirm everything works.
4. Map roles
Under Group to role mapping, map claim values, such as group names or app roles, to AIG roles. Set a Default role and decide whether to switch on Create an account on first sign-in.
5. Require single sign-on (optional)
First mark a break-glass account on the Users screen. Then switch on Require single sign-on and apply.
6. Add SCIM provisioning (optional)
At the bottom of the screen, under Directory provisioning (SCIM), click Create token. The token is shown once, so copy it straight away. In your directory's SCIM 2.0 provisioning app, enter the SCIM base URL (https://<your-gateway>/scim/v2) and the token.
What happens after you connect
- At every sign-in, roles are replaced based on your mappings. Without mappings, you assign roles by hand and the default role only applies to users who have none.
- Users are matched on the identity provider's stable subject ID, so a changed e-mail address does not create a duplicate. An existing local account is adopted once, by e-mail address.
- With SCIM, users and groups flow from your directory to AIG. Groups become teams and can grant roles. A delete in the directory deactivates the account but never deletes it, and deactivation ends open sessions on all nodes.
- Hand-made local accounts are never re-roled by sync.
Good to know
- AIG works with OpenID Connect only. SAML 2.0 is not supported.
- The issuer must match exactly, trailing slash included.
- Requiring single sign-on stays blocked until an active break-glass account exists.
Troubleshooting
- "Single sign-on did not complete. Contact an administrator." All sign-in failures look the same on purpose. Check that the user exists or that account creation on first sign-in is on, and that the account is not deactivated.
- "Set an issuer first." or "The provider did not answer as an OpenID Connect issuer." Check the issuer URL, including the trailing slash.
- "Mark an active user as a break-glass account before requiring single sign-on." Mark one on the Users screen first.
- SCIM returns 401 "The credentials presented are not valid.": the token is revoked or unknown. Create a new one.
Read more about SSO, SCIM and roles and about virtual keys for your applications.
Want to see single sign-on with your own identity provider before you roll it out? Talk to us about AIG.
