Skip to content

Single sign-on and provisioning

Single sign-on over OpenID Connect or SAML, SCIM provisioning and LDAP.

Let people sign in to Quire with the account they already have, and keep Quire’s user list in step with your directory.

Open /admin/security/auth, then Identity providers and directories, to add a connection. Each connection shows the addresses your identity provider needs.

OpenID Connect

Works with Microsoft Entra ID, Google Workspace, Okta, Auth0, Keycloak and any standards-compliant provider.

  1. In your identity provider, create a web application. Set its redirect address to the callback address Quire shows for the connection: https://<organisation>.quirelms.com/api/auth/sso/callback/<connection>.
  2. In Quire, choose Add OpenID Connect and enter the provider’s discovery address (ending /.well-known/openid-configuration), the client ID and the client secret. The secret is stored sealed; only its last four characters are shown again.
  3. Choose which email domains the connection serves. Someone signing in with an address at that domain is sent to your provider.

Vendor notes

  • Microsoft Entra ID: use the tenant’s own discovery address (https://login.microsoftonline.com/<directory id>/v2.0/.well-known/openid-configuration), not common. Quire signs people in on the email claim, which Entra sends only for accounts with a mail address. To map groups to roles, add the groups claim to the ID token and map the group object ids. With more than 200 groups Entra sends a pointer instead of the list and Quire grants no group role, so assign the application to specific groups or use app roles.
  • Okta: use https://<your-domain>/.well-known/openid-configuration (or an /oauth2/<server> address for a custom authorization server), add the groups scope and a groups claim, and map the group names. The sign-in page preset Okta (under social sign-in) needs only your Okta domain, such as acme.okta.com, the client ID and the secret.
  • Google Workspace: use https://accounts.google.com/.well-known/openid-configuration and list your domain in the connection, so an account at another domain is not signed in.

SAML 2.0

SAML single sign-on is part of the Business plan and above (see plan and billing). On a plan without it you cannot add a connection. If a plan later loses it, an existing connection stays readable but is left out of the sign-in methods, so plan for another way in before you downgrade.

  1. In Quire, choose Add SAML 2.0. Give your identity provider Quire’s details:

    • Metadata: https://<organisation>.quirelms.com/api/auth/sso/saml2/sp/metadata
    • Assertion consumer service (ACS): https://<organisation>.quirelms.com/api/auth/sso/saml2/sp/acs/<connection>
  2. From your identity provider, give Quire its metadata address, or paste its metadata XML, or enter its sign-in address and signing certificate.

  3. Send the email address as the name ID, and the given name and family name as attributes.

    Microsoft Entra ID sends the email as http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress, the name as http://schemas.microsoft.com/identity/claims/displayname and groups as http://schemas.microsoft.com/ws/2008/06/identity/claims/groups; enter those names as the attribute mapping. Okta sends whatever attribute statements you define; use email, displayName and a groups group attribute statement. Either name ID format works, because Quire reads the email from the attribute.

Testing

Sign in from a private browser window with a test account before telling everyone. Keep one administrator who can sign in with a password until single sign-on is proven, so a misconfiguration cannot lock everyone out.

Provisioning with SCIM

SCIM 2.0 lets your directory create, update and suspend Quire users, and manage group membership, without anyone uploading a spreadsheet.

  1. At /admin/security/auth, under User provisioning (SCIM), create a token. It is shown once.
  2. In your identity provider’s provisioning settings, set the SCIM base address to https://<organisation>.quirelms.com/scim/v2 and the token as a bearer token.
  3. Assign users and groups to the application.

Removing someone in the directory suspends them in Quire rather than deleting them, so their grades and certificates are kept. Every change SCIM makes is in the audit log under the token’s name.

LDAP

For an on-premises directory without SAML or OpenID Connect, add a LDAP directory connection with the server address, a bind account, and the base under which users are found. People then sign in with their directory password, which Quire checks against the directory and never stores.

Navigation

Type to search…

↑↓ navigate↵ selectEsc close