# Configure Identity Provider (IdP)

**Note**  
This section is only available for Sonatype Cloud.

1. In my.sonatype.com, navigate to _Settings → Organizations_, and select the Organization you'd like to manage.

2. Select the _Identity Management_ tab.

3. Select the _Connect IDP_ button and follow the on-screen instructions to link your instance’s URL to your IdP.

After setting up an IdP, you can remove it or edit it from this tab.

Select the _Enable Identity Provider Groups_ checkbox to manage access via IdP groups rather than individual users.

Note that you also need to configure your specific IdP to send group membership (for example, a `groups` claim) in its token/assertion. If the IdP isn’t configured (or permissions/consent are missing), group sync may fail and users may see an IdP permissions error during sign-in.

## Configuring Specific IdPs

**Note**  
Sonatype’s self-service single sign-on (SSO) is powered by [Auth0](https://auth0.com/). For background and the most up-to-date details, see Auth0’s official documentation:

- [How self-service SSO works](https://auth0.com/docs/authenticate/enterprise-connections/self-service-SSO)

- [Enterprise identity providers supported by Auth0](https://auth0.com/docs/authenticate/identity-providers/enterprise-identity-providers)

### [Microsoft Entra ID](https://help.sonatype.com/en/configure-identity-provider.html#micrososft-entra-id_body)

**Note**  
For provider-specific configuration details and troubleshooting, see [Auth0’s official documentation for Microsoft Entra ID / Azure AD Enterprise connections](https://auth0.com/docs/authenticate/identity-providers/enterprise-identity-providers/azure-active-directory/v2).

#### Step-by-Step Entra ID Instructions

##### Step 1: Create Application

To connect your Entra ID tenant as an identity provider, you must create an OIDC application.

01. Navigate to _App Registration_. Then, select _New Registration_.

02. Enter a _name for the application_.

03. Under _Selected account types_, choose _Accounts in this organization directory only (Default Directory only - Single tenant)_.

04. Select _Register_.

05. Copy your _Application (client) ID_. You will use it in the next step to configure your connection.

06. Under _Redirect URIs_, select _Add a Redirect URI_.

07. Under _Platform Configurations_, select _Add a platform_ and choose _Web_ as the platform.

08. Add the _Callback URL_ in the _Redirect URIs field_.  
   Callback URL. `https://identity.sonatype.com/login/callback`

09. Select _Configure_.

10. Select _Certificates & secrets_ in the left-hand navigation, and then select _New client secret_.

11. Enter a _Description_ and set the _expiration_.

12. Click _Add_ then copy the _Value_.

13. Click _Add_ then copy the client secret _Value_.

##### Step 2: Configure Connection

Establish a connection between your identity provider and Sonatype.

1. Open the organization to set up an IdP.

2. Click the _Identity Provider_ tab.

3. Click the _Connect IDP_ button, and select Entra ID.

Microsoft Entra ID Domain

Your Entra ID domain (e.g., `example.onmicrosoft.com`).

Client ID

The Application (client) ID you copied from the Azure portal.

Client Secret

The client secret value you copied from the Azure portal.

##### Step 3: Claims Mapping

Claims mapping ensures that the correct user attributes are applied from the identity provider to the service provider.

Required Claims. Add the following claims in Entra ID:

- `groups` \- Groups the user belongs to. They can be used from product to assigning product roles.
- `email` \- User's email address.

Optional Claims. Your users will be able to log in without mapping these claims but providing them will enhance the end user experience:

- `family_name` \- User's last name
- `given_name` \- User's first name
- `name` \- User's full name

**Note**  
For more information on adding claims, see [Microsoft's documentation](https://learn.microsoft.com/en-us/entra/identity-platform/jwt-claims-customization#view-or-edit-claims).

##### Step 4: Assign Access

Grant users or groups access to Sonatype.

1. Navigate to _Enterprise applications_ and select the application you created. Then, select _User and groups_.

2. Select _Add user/group_.

3. Under _Users_, select _None selected_.

4. Select the users you want to assign access to this application.

5. Click _Select_.

6. Select _Assign_.

##### Step 5: Test SSO and Enable Connection

Test the connection to ensure SSO setup is successful.

1. Select _Test Connection_. This will open a new window and redirect you to log in with Entra ID. You'll receive an OIDC response in return.

**Important**  
Please do not close out the window while testing.

2. After successfully testing the connection, select _Enable Connection_ to activate SSO for your organization.

#### Notes for Configuring Entra ID

- As part of the onscreen setup you will be prompted to add _Group Claims_ and _Optional Claims_. Refer to [Microsoft Entra documentation](https://learn.microsoft.com/en-us/entra/identity-platform/optional-claims?tabs=appui) for detailed guidance.
- The _Identity Provider Groups_ feature requires the following Entra ID configuration:

1. After selecting your application, go to _Manage_ \> _API Permissions_ \> _Add a Permission_ to open the _Request API Permissions_ drawer.

2. Under the _APIs my organization uses_ tab, select _Microsoft Graph_

3. Select _Delegated Permissions_. In the Select Permissions search bar, type `Directory.Read.All`. Then, expand the _Directory_ section, check _Directory.Read.All_, and select _Add permissions_.

**Note**  
     After adding permissions, ensure your tenant admin grants consent if required by your organization’s policy.

### [Okta](https://help.sonatype.com/en/configure-identity-provider.html#okta_body)

**Note**  
For provider-specific configuration details and troubleshooting, see [Auth0’s official documentation for Okta Enterprise connections](https://auth0.com/docs/authenticate/identity-providers/okta).

These steps assume you’ve already created a new IdP configuration in my.sonatype.com, and you’re now entering the corresponding values in your IdP admin console.

#### Step-by-Step Okta Instructions

##### Step 1: Create Application

To connect your Okta tenant as an identity provider, you must create an OIDC application.

1. Select _Applications > Applications_, and _Create App Integration_.

2. Select _Create New App_.

3. Choose _OIDC_ as the _Sign-in method_. Choose _Web Application_ as your _Application Type_.

4. Select _Next_.

5. Enter your _App integration name_.

6. Add the callback URL in the _Sign-in redirect URIs_ field.
   Callback URL. `https://identity.sonatype.com/login/callback`

7. Select _Save_. Make sure to copy your _Client ID_ and _Client Secret_ as you will use them in the next step to configure your Okta connection.

##### Step 2: Configure Connection

Establish a connection between Okta and Sonatype.

1. Open the organization to set up an IdP.

2. Click the _Identity Provider_ tab.

3. Click the _Connect IDP_ button, and select Okta.

Okta Domain

Enter your Okta domain (e.g., `domain-name.okta.com`).

For help finding your Okta domain, see: [Where do I find the Okta domain?](https://developer.okta.com/docs/guides/find-your-domain/main/)

Client ID

Unique identifier for the client application or service integration.

For help finding your Client ID, see: [Where do I find the Client ID?](https://developer.okta.com/docs/guides/find-your-app-credentials/main/)

Client Secret

Confidential token used for client authentication.

For help finding your Client Secret, see: [Where do I find the Client Secret?](https://developer.okta.com/docs/guides/find-your-app-credentials/main/)

##### Step 3: Claims Mapping

Claims mapping ensures that the correct user attributes are applied from the identity provider to the service provider.

Required Claims. Add the following claims in Okta:

- `groups`
- `email`

**Important**  
When configuring the `groups` claim in Okta, ensure that the claim is returned as a comma-separated string, not as a JSON array. If Okta returns groups as an array, users may authenticate successfully but receive no external role mappings.

Optional Claims. Your users will be able to log in without mapping these claims but providing them will enhance the end user experience:

- `family_name`
- `given_name`
- `name`

##### Step 4: Assign Access

Grant users or groups access to Sonatype.

1. Select _Assignments_ in the horizontal tabs within the application you just created in Okta.

2. Select _Assign_, then _Assign to Groups_.

3. Select _Assign_ for the groups you want to assign access to this application.

4. Select _Done_

##### Step 5: Test SSO and Enable Connection

Test the connection to ensure SSO setup is successful.

1. Select _Test Connection_. This will open a new window and redirect you to log in with Okta. You'll receive an OIDC response in return.

**Important**  
Please do not close out the window while testing.

2. After successfully testing the connection, select _Enable Connection_ to activate SSO for your organization.

### [Google Workspace](https://help.sonatype.com/en/configure-identity-provider.html#id636352_body)

**Note**  
For provider-specific configuration details and troubleshooting, see [Auth0’s official documentation for Google Workspace / Google SSO Enterprise connections](https://auth0.com/docs/authenticate/identity-providers/enterprise-identity-providers/google-apps).

#### Step 1: Create Application

To connect your Google tenant as an identity provider, you must create an OIDC application.

1. Go to the [Google Developer Console](https://console.cloud.google.com/) and choose the project to add your new application to or create a new project.

2. Select _APIs & Services_ from the dashboard, then _Credentials_ in the left-hand navigation.

3. Click _Create Credentials_ and select _OAuth client ID_.

4. Choose _Web application_ as your _Application type_.

5. Enter a _Name_ for the application and add the _Authorized Javascript Origins_ and _Authorized Redirect URIs_ below.
   Authorized Javascript Origins URI. `https://identity.sonatype.com`
   Authorized Redirect URI. `https://identity.sonatype.com/login/callback`

6. Select _Create_.

7. Make sure to copy your _Client ID_ and _Client secret_ as you will use them in the next step to configure your Google connection.

#### Step 2: Configure Connection

Establish a connection between Google Workspace and Sonatype.

1. Open the organization to set up an IdP.

2. Click the _Identity Provider_ tab.

3. Click the _Connect IDP_ button, and select Google Workspace.

Google Workspace Domain.

Your Google Workspace domain (e.g., `example.com`).

For more information, see [Where do I find the Google Workspace Domain?](https://support.google.com/domains/answer/7278940)

Client ID.

Copy the client ID you created in the Google Cloud Console (API & Services → Credentials).

Client Secret.

Copy the corresponding Client Secret from the Credentials page.

#### Step 3: Assign Access

Grant users or groups access to Sonatype.

1. Go to the [Google Admin Console](https://admin.google.com/) and select _Directory > Organizational units_ in the left-hand navigation.

2. If applicable, select _Create organizational unit_ to create a unit under your primary unit.

3. Go to _Directory > Users_ and add a new user or select an existing one.

4. Within the selected user, click _Change organizational unit_ and choose the applicable unit.

5. Go to _Security > Access and data control > API controls_ in the left-hand navigation and click _Manage Third-Party App Access_.

6. Select _Add app_, then _OAuth App Name Or Client ID_.

7. Paste the client ID from the application you created in the _Search for OAuth app name or client ID_ field and _Search_.

8. Click _Select_ on your application.

9. Click on the selected app and _Access to Google data_ to assign organization units access and _Save_.

#### Step 4: Test SSO and Enable Connection

Test the connection to ensure SSO setup is successful.

1. Select _Test Connection_. This will open a new window and redirect you to log in with Google Workspace. You'll receive an OIDC response in return.

**Important**  
Please do not close out the window while testing.

2. After successfully testing the connection, select _Enable Connection_ to activate SSO for your organization.

### [PingFederate](https://help.sonatype.com/en/configure-identity-provider.html#id636474_body)

**Note**  
For provider-specific configuration details and troubleshooting, see [Auth0’s official documentation for PingFederate Enterprise connections](https://auth0.com/docs/authenticate/identity-providers/enterprise-identity-providers/ping-federate).

#### Step 1: Create SP Connection

To connect your PingFederate tenant as an identity provider, you must create a SAML SP connection.

1. Select _Applications_ in the top navigation, then _SP Connections_.

2. Select _Create Connection_.

3. Select _Do not use a template for this connection_, then _Next_.

4. Select _Browser SSO Profiles_ and _SAML 2.0_ as the _Protocol_, then click _Next_.

5. Proceed to the _General Info_ page and enter the following _Partner's Entity ID_ and a custom _Connection Name_.
   Partner's Entity ID. `urn:auth0:sonatype:self-service-demo-trial`

6. Select _Next_.

#### Step 2: Configure Browser SSO

To connect your PingFederate tenant as an identity provider, you must configure browser SSO.

1. You should now be on the _Browser SSO_ page.

2. Select _Configure Browser SSO_.

3. Under _Single Sign-On (SSO) Profiles_, select _SP-INITIATED SSO_, then click _Next_.

#### Step 3: Configure Assertion Creation

To connect your PingFederate tenant as an identity provider, you must configure assertion creation.

01. Proceed to the _Assertion Creation_ page and select _Configure Assertion Creation_.

02. On the _Identity Mapping_ page, make sure _STANDARD_ is selected, then click _Next_.

03. On the _Attribute Contract_ page, select the _SAML_SUBJECT_ as _urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress_.

04. Under _Extend the Contract_, enter the following attributes and map them to the relevant _Attribute Name Format_. Click _Add_ for each attribute.

Required Attributes. Map the following attribute statements in your identity provider:

groups

Groups the user belongs to. They can be used from product to assigning product roles.

email

User's email address.

Optional Attributes. Your users will be able to log in without mapping these attributes but providing them will enhance the end user experience:

family_name
    User's last name

given_name
    User's first name

name
    User's full name

05. Select _Next_.

06. On the _Authentication Source Mapping_ page, select _Map New Adapter Instance_.

07. Select an existing _Adapter Instance_ or create a new one.

08. Proceed with configurations relevant to your organization's authentication requirements, then select _Done_ on the last page.

09. You should now be back on the _Authentication Source Mapping_ page.

10. Select _Map New Authentication Policy_.

11. Select an existing _Authentication Policy Contact_ or create a new one by selecting _Manage Policy Contacts_.

12. On the _Mapping Method_ page, make sure _USE ONLY THE AUTHENTICATION POLICY CONTRACT VALUES IN THE SAML ASSERTION_ is selected, then click _Next_.

13. On the _Attribute Contract Fulfillment_ page, map each _Attribute Contract_ to the corresponding _Value_.

14. Select _Next_. Then, proceed to the _Summary_ and select _Done_.

#### Step 4: Configure Protocol Settings

To connect your PingFederate tenant as an identity provider, you must configure protocol settings.

1. On the _Protocol Settings_ page, select _Configure Protocol Settings_ and click _Next_.

2. On the _Assertion Consumer Service URL_ page, add the following endpoint URL:
   Endpoint URL. `https://identity.sonatype.com/login/callback?connection=self-service-demo-trial`

3. Set the _Binding_ to _POST_ as the default, and ensure _Allowable SAML Bindings_ includes both _POST_ and _REDIRECT_.

4. Select _Next_ through the remaining protocol settings screens, accepting the defaults.

#### Step 5: Configure Credentials

To connect your PingFederate tenant as an identity provider, you must configure credentials.

1. On the _Credentials_ page, select _Configure Credentials_ and click _Next_.

2. On the _Digital Signature Settings_ page, ensure the _Signing Certificate_ is selected.

3. Verify that _Include the certificate in the signature <KeyInfo> element_ is checked.

4. Select _Next_.

5. Review the summary and select _Next_.

6. On the _Activation & Summary_ page, set the connection to _Active_ and select _Save_.

#### Step 6: Configure Connection

Establish a connection between your identity provider and Sonatype.

1. Open the organization to set up an IdP.

2. Click the _Identity Provider_ tab.

3. Click the _Connect IDP_ button, and select PingFederate.

Single Sign-On Login URL

Endpoint for initiating secure authentication in SAML SSO connections.

To obtain the Single Sign-On Login URL, navigate to the _SP Connections_ page and select _Export Metadata_. Look for the _SingleSignOnService_ assertion tag in the metadata and copy the associated URL.

Example: `https://your.PingFederate.server/idp/SSO.saml2`

Signing Certificate

Digital credential used for secure identity authentication.

To obtain the Signing Certificate, navigate to _SP Connections > SP Connection > Credentials > Certificate Management_ and select _Export_.

Advanced Settings. The following advanced settings are available for customizing your SAML connection:

Sign Request

When enabled, the SAML authentication request will be signed. Download the certificate and provide it to the SAMLP that will receive the signed assertion to validate the signature.

### [Custom OIDC](https://help.sonatype.com/en/configure-identity-provider.html#id636709_body)

**Note**  
For generic OIDC setup guidance (endpoints, scopes, claims, redirect URI rules), see [Auth0’s official documentation for Custom OIDC (generic OpenID Connect) Enterprise connections](https://auth0.com/docs/authenticate/identity-providers/enterprise-identity-providers/oidc).

#### Step 1: Create an Application

Create a generic OIDC application in your identity provider.

- Copy and paste the _Callback URL_ in the corresponding field in your identity provider.
  Callback URL. `https://identity.sonatype.com/login/callback`

Destination where authentication and authorization responses are received, enabling secure user access handling. Also known as: _Sign-in Redirect URI_, _Login Redirect URI_.

#### Step 2: Configure Connection

Establish a connection between your identity provider and Sonatype.

1. Open the organization to set up an IdP.

2. Click the _Identity Provider_ tab.

3. Click the _Connect IDP_ button, and select OIDC.

OpenID Provider Configuration Endpoint

Enter the URL of the discovery document of the OpenID Connect provider you want to connect with.

Example: `https://example.com/.well-known/openid-configuration`

Communication Channel

Select whether authentication exchanges occur via server-to-server communication (_Back Channel_) or through the browser using Implicit Flow with Form Post (_Front Channel_).

Client ID

Unique identifier for client application or service integration.

Client Secret

Confidential token used for client authentication.

### [Custom SAML](https://help.sonatype.com/en/configure-identity-provider.html#id636763_body)

**Note**  
For generic SAML setup guidance (ACS/SSO URL, Entity ID, certificate, attribute mappings), see [Auth0’s official documentation for Custom SAML Enterprise connections](https://auth0.com/docs/authenticate/identity-providers/enterprise-identity-providers/saml).

#### Step 1: Create an Application

Create a generic SAML application in your identity provider.

- Copy and paste the _Single Sign-On URL_ and the _Service Provider Entity ID_ in the corresponding field in your identity provider.
  Single Sign-On URL. `https://identity.sonatype.com/login/callback?connection=self-service-demo-trial`
  Service Provider Entity ID. `urn:auth0:sonatype:self-service-demo-trial`

#### Step 2: Configure Connection

Establish a connection between your identity provider and Sonatype.

1. Open the organization to set up an IdP.

2. Click the _Identity Provider_ tab.

3. Click the _Connect IDP_ button, and select SAML.

Metadata URL

Location to retrieve SAML SSO connection information for integration.

Example: `https://example.com/samlp/metadata.xml`

Advanced Settings. The following advanced settings are available for customizing your SAML connection:

Sign Request

When enabled, the SAML authentication request will be signed. Download the [certificate](https://identity.sonatype.com/pem?cert=connection) and provide it to the SAMLP that will receive the signed assertion to validate the signature. This needs to be enabled first in the SAMLP. Once enabled, share the metadata URL for integration.

Request Protocol Binding

Choose between _HTTP-Post_ or _HTTP-Redirect_ for the SAML request protocol binding.

**Note**  
For SAML connections, ensure the SAML assertion includes `email` as a required field. Users won’t be able to authenticate if `email` is missing.
