SSO with a dedicated OIDC Client
Learn how to set up Single Sign-On (SSO) for findIQ through your Identity Provider using the OIDC protocol.
Written By Tommy Giesbrecht
Last updated 6 months ago
This article describes how to set up Single Sign-On (SSO) for findIQ through your Identity Provider (IdP) using a dedicated OIDC Client. After reading, you will know which configuration steps are required and what information to share with the findIQ team.
You can access this area with the Administrator role.
What is SSO via OIDC?
Article goal: After reading this article, you will know how to create an OIDC client in your Identity Provider, configure the appropriate claim mapper, and activate the connection to findIQ.
How to set up SSO via OIDC
To set this up, you need administrator access to your Identity Provider and contact with the findIQ team.
1. Create an OIDC client in your Identity Provider
Create a new OIDC client in your Identity Provider with the following settings:
Enable Client Authentication (type: confidential)
Root URL (optional, depending on IdP):
https://app.findiq.deRedirect URL:
https://app.findiq.de/auth/realms/api_main/broker/oidc/endpoint
2. Configure claim mapper
Create a new role for the token roles claim (sometimes called a “dedicated client role”)
Include the role name (token value):
{organisation}/{role}
You can find your organization name inside the URL of the findIQ app. For example, a valid token value for the organization at https://app.findiq.de/app/MyCompany/machines can be MyCompany/Operator
Make sure the claim is included in the Access Token roles attribute.
Available roles
3. Send information to findIQ
Send the following information to the findIQ team:
The discovery endpoint of your Identity Provider (ends with
/.well-known/openid-configuration)The generated Client ID
The generated Client Secret
The type of client authentication used (default: "Client Secret send as POST")
4. Set IdP hint in the URL
To redirect users directly to your Identity Provider (bypassing the findIQ login page), append the idp_hint query parameter to the URL:
https://app.findiq.de/standalone/{organisation}/{machine_uid}/diagnose/?idp_hint={idp_alias}You will receive the {idp_alias} value from the findIQ team after the configuration is complete.
Important Notes
The entire setup requires coordination with the findIQ team. Plan sufficient time for this.
Test the SSO login with a test user before enabling access for all users.
Make sure the
rolesclaim is included in the Access Token.
FAQ
Which Identity Providers are supported?
Which Identity Providers are supported?
findIQ supports any Identity Provider that implements the OIDC protocol (OpenID Connect) - Microsoft Entra ID / Azure AD, Okta, Keycloak, Auth0, ADFS, or Google Workspace.
Can I assign multiple roles or organizations?
Can I assign multiple roles or organizations?
For multiple or complex assignments, please contact the findIQ team.
What happens if the claim is missing or incorrect?
What happens if the claim is missing or incorrect?
If the roles claim is not included in the Access Token or has an invalid value, the user will still be able to sign in to findIQ, but the user will not be automatically assigned and synchronized into your enviroment. Thus, you have to sent them a dedicated invitation email.
How can i change permissions of users and groups after their registration?
How can i change permissions of users and groups after their registration?
If you reassign or change the role of individual users or whole groups of users inside of your Identity Provider, the new role will be automatically synchonized in findIQ for the targeted users. This process usually takes some time to take effect.