Single sign-on with your identity provider
Single sign-on lets your people log in to RapidValue with the account they already use for everything else. You set it up in two places: first your identity provider (IdP), where you register RapidValue as an application, and then RapidValue under Environment & connections → SSO / Identity Provider.
RapidValue supports:
| Provider | Protocol | Section |
|---|---|---|
| Microsoft Entra ID (Azure AD) | OpenID Connect | Microsoft Entra ID |
| Any SAML 2.0 IdP (Okta, Entra enterprise apps, ADFS, PingFederate, Google Workspace, …) | SAML 2.0 | SAML 2.0 |
Before you start
- You need two admins, or one person with both roles: a tenant admin in RapidValue, and someone who can register applications and grant admin consent in your IdP.
- People need a RapidValue login before they can sign in with SSO. SSO proves who someone is; it never creates a login. Logins come from an invitation, or from creating logins out of synced identities under Platform access. Sync your directory first (for example with the Microsoft Entra ID connector): then RapidValue can recognise one person behind several addresses.
- Keep a way back in. When SSO is enabled for an email domain, password login for that domain is refused ("This email domain uses SSO"). Keep your current admin session open until an SSO login has worked, and keep at least one admin account on another domain.
The right-hand card on the SSO screen, Values to enter in your IdP, always shows the exact values for your environment, with a copy button. Use those rather than typing them from this page.
Microsoft Entra ID
1. Register the application
In the Microsoft Entra admin center: Identity → Applications → App registrations → New registration.
| Field | Value |
|---|---|
| Name | RapidValue (any name your users will recognise on the consent screen) |
| Supported account types | Accounts in this organizational directory only (single tenant) |
| Redirect URI | Platform Web, value: the Redirect / callback URI from the SSO screen, e.g. https://app.rapidvalue.eu/api/v1/auth/oidc/callback |
Choose Register.
The platform must be Web. Not Mobile and desktop applications and not Single-page application: with those, Entra treats RapidValue as a public client and refuses the sign-in when RapidValue presents its client secret. If you added the URI under another platform, remove it there and add it under Web. Under Authentication, keep Allow public client flows set to No.
2. Copy the identifiers
On the application's Overview page:
- Directory (tenant) ID → you need it for the Authority URL.
- Application (client) ID → goes into Client ID in RapidValue.
3. Create a client secret
Certificates & secrets → Client secrets → New client secret.
Copy the Value column immediately; it is shown only once. The Secret ID column is not the secret. Note the expiry date. When the secret expires, SSO logins fail at the token exchange, so put a renewal reminder in your calendar.
4. API permissions
API permissions should contain Microsoft Graph delegated permissions
openid, profile and email (User.Read is there by default and may
stay). Choose Grant admin consent for
5. Fill in the SSO screen in RapidValue
| RapidValue field | Value |
|---|---|
| Provider type | Microsoft Entra ID (Azure AD) |
| Authority / Issuer URL | https://login.microsoftonline.com/<directory-tenant-id>/v2.0 |
| Client ID | the Application (client) ID |
| Client secret | the secret Value from step 3 |
| Email domain | the domain your people log in with, e.g. example.com |
| Email claim | leave empty (see Which email address is used) |
Switch Enable SSO on and choose Save. RapidValue refuses to enable a configuration without an Authority URL or Client ID. Then test it before you log out.
The client secret is write-only: after saving, the field shows that a secret is stored. Leave it empty on later edits to keep the stored secret; type a new one to replace it.
SAML 2.0
Use this for Okta, Google Workspace, ADFS, PingFederate, or an Entra enterprise application if you prefer SAML over OpenID Connect.
1. Create the SAML application in your IdP
Take these values from Values to enter in your IdP (choose provider type SAML first, so the card shows the SAML values):
| IdP field (names vary per IdP) | Value |
|---|---|
| Audience / SP Entity ID / Identifier | the SP Entity ID, e.g. https://app.rapidvalue.eu/api/v1/auth/saml/metadata |
| ACS URL / Single sign-on URL / Reply URL | the ACS URL, e.g. https://app.rapidvalue.eu/api/v1/auth/saml/acs |
| Name ID format | EmailAddress |
| Name ID value | the user's email address |
Assertions must be signed. Both SP-initiated login (starting from the RapidValue login page) and IdP-initiated login (clicking the app tile in your IdP portal) work.
2. Fill in the SSO screen in RapidValue
| RapidValue field | Value |
|---|---|
| Provider type | SAML 2.0 |
| IdP SSO URL | your IdP's SAML single sign-on URL (HTTP-Redirect binding) |
| IdP Entity ID | your IdP's issuer / entity ID |
| IdP Certificate (PEM) | the IdP's signing certificate (-----BEGIN CERTIFICATE----- …) |
| Email domain | the domain your people log in with |
| Email claim | optional: the attribute that carries the email address; empty = the Name ID |
The certificate is write-only, like the client secret: leave the field empty on later edits to keep the stored one.
Okta and other OpenID Connect providers
The provider type list also shows Okta and Generic OIDC. Today RapidValue derives the discovery address the way Microsoft Entra publishes it, so for Okta and other OpenID Connect providers, use SAML 2.0 as described above.
Which email address is used
After the first sign-in, RapidValue recognises the person by the identity provider's own permanent ID for them, not by an address:
- Microsoft Entra ID: the directory ID plus the user's object ID;
- other OpenID Connect providers: the provider's subject ID;
- SAML: a persistent NameID.
A rename or a second address in the identity provider therefore does not create a second RapidValue login.
For the first sign-in, RapidValue finds the existing login in this order:
- Microsoft Entra ID with the Entra connector: the synced account with the
same object ID leads to the person and their login. This is how one person
with two addresses (for example
name@example.comandname@example.eu) lands on the one login they already have. - The sign-in name (Entra
upn/preferred_username, or the SAML address), but only when it is in one of your SSO email domains. Guest accounts are never matched this way. - The email address in the token, again only inside your SSO email domains. For an OpenID Connect provider other than Entra, only when the provider marks the address as verified.
Addresses are compared case-insensitively. For Microsoft Entra ID, leaving Email claim empty works for most tenants.
The Email domain field is what makes the login page send someone to your
IdP: when a user types name@example.com and example.com has SSO enabled,
they are redirected. If the same domain has SSO enabled in more than one
tenant, the shared login page cannot tell which one is meant, and users log in
through their tenant's own URL instead.
What happens at the first SSO login
- An existing login: RapidValue links it to the identity provider's ID for the person, and they are signed in with the roles they already have. The link is visible under Platform access → the login → SSO sign-in links.
- No login yet: the sign-in is refused with "You don't have access to
RapidValue with this account yet". The attempt is recorded in the audit log
(
AUTH_SSO_REFUSED), with who tried. Invite the person, or create logins out of synced identities, if they should have access. - Refused for safety:
- a sign-in that matches more than one login;
- a login that is already linked to a different account at the same identity provider (for example a re-used address of someone who left);
- an account an admin has blocked.
An admin sorts these out in Platform access.
To undo a wrong link, choose Unlink and block on the login. That account can then no longer sign in, and the login is signed out everywhere. Allow again lifts the block; the next sign-in is then matched from scratch.
Test it
- Keep your current admin session open.
- Open a private browser window, go to the login page and enter an address on the SSO domain. You should be sent to your IdP and come back logged in.
- In your admin session, open Platform access, find the login and check under SSO sign-in links that it is linked to the right account.
Troubleshooting
| What you see | Likely cause |
|---|---|
Microsoft: AADSTS50011 (redirect URI mismatch) |
The Redirect URI in the app registration differs from the one on the SSO screen. Copy it again; it must match exactly, including https and the path. |
"Token exchange failed with IdP" right after signing in at Microsoft, or AADSTS700025 |
The redirect URI is registered under Mobile and desktop applications (or Single-page application) instead of Web, or Allow public client flows is on. Move the URI to Web and set public client flows to No. |
Microsoft: AADSTS7000215 (invalid client secret) |
You copied the Secret ID instead of the Value, or the secret expired. Create a new secret and save it in RapidValue. |
Microsoft: AADSTS65001 (consent required) |
Admin consent was not granted. Grant it under API permissions. |
| "Token exchange failed with IdP" | The client secret is wrong or expired, or the redirect URI differs. |
| "No email in IdP token" | None of the claims in Which email address is used carries an address. Set Email claim to the right claim, or add the email optional claim in the IdP. |
| "IdP is not fully configured" | Authority URL or Client ID is empty (OIDC), or IdP SSO URL, IdP Entity ID or certificate is missing (SAML). |
| "This email domain uses SSO" at password login | Expected: SSO is enabled for this domain. Use the SSO login, or log in as an admin on another domain. |
| "This email domain uses SSO in multiple tenants" | Two tenants claim the same email domain. Log in through your tenant's own URL. |
| "You don't have access to RapidValue with this account yet" | There is no login for this person, the account was blocked, or it matched more than one login. The audit log (AUTH_SSO_REFUSED) says which. |
Related
- Microsoft Entra ID connector: syncing your people and groups, with its own app registration and read permissions.