Note:
Depending on your SundaySky plan, SSO may be included or offered as an add-on. For questions about availability, contact your SundaySky Account Team or SundaySky Support.
Overview
Single Sign-On (SSO) is an authentication method that allows your corporate IT team to manage user authentication to the SundaySky platform using your organization's Identify Provider (IdP).
SSO simplifies login for end users by removing the need for separate credentials, and it helps IT administrators maintain centralized control and better security.
Once your SundaySky account is configured for SSO, users will be redirected to your company's internal SSO login page to access SundaySky. After successful authentication, they'll be automatically logged into the SundaySky platform.
Enabling SSO
Step 1: Contact Your SundaySky Success Manager
Let your Success Manager know that you're interested in enabling SSO authentication. SundaySky will provide you with a SAML (XML) metadata file, which includes:
▶ Our entity ID
▶ Public certificate
▶ Login/redirect URL
▶ Other required service provider details
Step 2: Set Up SundaySky in Your Identity Provider
Use the provided metadata file to configure SundaySky as a service provider (SP) in your Identity Provider.
Step 3: Provide Relevant Details to SundaySky
Once SundaySky is added to your Identity Provider, provide the following details to your Success Manager:
▶ Identity Provider Single Sign-On URL
▶ X.509 certificate
Note: If your IdP provides a metadata endpoint, you can share that instead of individual details as SundaySky supports XML metadata files from IdP endpoints.
Step 4: Identify a Test User
Update SundaySky regarding the user that should be set up for initial testing. Once that user can successfully log in via SSO, SundaySky will:
▶ Convert all existing users to SSO
▶ Ensure any future users follow the same configuration
Integration Notes
1. | SundaySky supports identity providers that use the SAML 2.0 protocol for authentication. OAuth is not currently supported. |
2. | SSO is used for authentication only. It does not provision users. |
3. | All users must be manually created in the SundaySky platform by an Account owner and assigned a user type before they can log in via SSO. |