OneLogin OIDC with multiple domains, using Google Identity Provider

Viewed 75

Currently trying to integrate our webapp (React) with OneLogin. We use Google Identity Provider for our authentication. I'm trying to add a button that says "Log in with OneLogin", but I don't know how to point it to multiple domains.

I added our OneLogin test app to Google as an OIDC and it works fine when pointed to our test app. But how do I point it to other domains?

I feel like I'm missing part of the puzzle here.

The flow would be like:

  1. Open our webapp
  2. Your org uses OneLogin, so you click "sign in with onelogin"
  3. You authenticate against onelogin, and it returns you to our webapp via OIDC/Google Iden Provider
  4. You are now logged into our system, and we can view your email address and name.

Does this require adding an app to OneLogin's store?

Sorry if I sound confused, because I definitely am lol.

Thanks in advance!

1 Answers

I think I understand what you are trying to do; It sounds as though you are trying to have multiple Trusted IdPs for your web app. If that is the case, this link shows how you can configure your app to point to another IdP.

  1. Go to Authentication > Trusted IdPs and select New Trust.

  2. Provide a name for the Trusted IdP configuration

  3. In the Trusted IdP Settings tab, check Enable Trusted IDP in the Enable/Disable field.

  4. In the Login Options section, if you wish to represent this Trusted IdP as an authentication option on the tenant’s login page via an icon, then check Show in Login panel and provide a url to a suitable icon. (Note; websites typically host a “favicon.ico” file that could be used e.g. https://www.onelogin.com/favicon.ico)

  5. In the Configurations section, enter the Issuer URL or issuer name for the third-party identity provider in the Issuer field. Note: This field only applies to SAML and OIDC (not OAuth).

  6. The Email Domains field is used to automatically invoke this Trusted IdP when a user enters their email address at login time - if the email address is unrecognized, but belongs to one of the domains listed, then this TIdP will be invoked via an authentication request (SAML, OIDC or OAuth as appropriate).

  7. To enable Standard mode, check Sign users into OneLogin. This allows inbound identities from the Identity Provider to be matched to local user accounts within the tenant, via responses to the /access/idp endpoint.

  8. To send the user identity within the authentication request sent to the Trusted Identity Provider, check Send Subject Name ID or Login Hint in Auth Request: if the Trusted IdP is configured to use SAML, then the authentication request is sent as a Subject NameID parameter whilst if OIDC or OAuth is used, the same information is sent as a query string parameter called login_hint. This feature is to provide an improved user experience by avoiding the need for the user to provide an identifier to both OneLogin and the Trusted IdP. More detailed instructions for the current process can be found at: Trusted IdP

Just in case you haven't ran across this yet. Onelogin OIDC

If you are still having issues, let me know how I can help

Related