Skip to main content
Connect AI supports SSO with multiple identity providers. To enable SSO for your account, contact CData Support.

Configure SSO in Your Identity Provider

CData Support initiates the SSO setup and provides the callback URL that you must register in your identity provider. After you register the application and gather the required credentials, send them to CData Support to complete the configuration. CData Support handles the broker-side setup (Auth0 configuration, rules, and routing). You do not handle those directly. For more information about configuring SSO, refer to Single Sign-On in the Auth0 documentation.

SSO User Provisioning (Without JIT)

SSO handles authentication only. Before a user can sign in via SSO, they must have a Connect AI account. Without JIT provisioning enabled, an Administrator must invite the user by email first. See Users for details.

JIT User Provisioning

Your account must already have SSO configured to enable JIT provisioning.
JIT provisioning automatically creates a user account the first time someone successfully authenticates through SSO. The Connect AI Administrator does not have to invite the user manually. The new user receives the role that has been configured by the Administrator in the Settings page (the Security tab) by turning on Just-in-Time User Provisioning for the selected email domain and role.
JIT Provisioning
An Administrator or User Administrator can modify the roles and permissions later. See Permissions and Access Control for details on user roles and permissions. If the new user’s SSO login reaches the maximum number of seats, the user’s provisioning is denied. The Administrator receives an alert.

Troubleshooting

For common questions and errors for each SSO provider, see the following troubleshooting guides: