---
title: "Single sign-on and provisioning"
description: "Single sign-on over OpenID Connect or SAML, SCIM provisioning and LDAP."
image: "https://docs.quirelms.com/og.png"
---

> Documentation Index
> Fetch the complete documentation index at: https://docs.quirelms.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Single sign-on and provisioning

<span id="single-sign-on-and-provisioning"></span>

Let people sign in to Quire with the account they already have, and keep
Quire's user list in step with your directory.

Open `/admin/security/auth`, then **Identity providers and directories**, to
add a connection. Each connection shows the addresses your identity provider
needs.

## OpenID Connect <!--quire:openid-connect-->

Works with Microsoft Entra ID, Google Workspace, Okta, Auth0, Keycloak and
any standards-compliant provider.

1. In your identity provider, create a web application. Set its redirect
   address to the **callback address** Quire shows for the connection:
   `https://<organisation>.quirelms.com/api/auth/sso/callback/<connection>`.
2. In Quire, choose **Add OpenID Connect** and enter the provider's
   discovery address (ending `/.well-known/openid-configuration`), the
   client ID and the client secret. The secret is stored sealed; only its
   last four characters are shown again.
3. Choose which email domains the connection serves. Someone signing in with
   an address at that domain is sent to your provider.

### Vendor notes <!--quire:vendor-notes-->

- **Microsoft Entra ID**: use the tenant's own discovery address
  (`https://login.microsoftonline.com/<directory id>/v2.0/.well-known/openid-configuration`),
  not `common`. Quire signs people in on the `email` claim, which Entra sends
  only for accounts with a mail address. To map groups to roles, add the
  groups claim to the ID token and map the group object ids. With more than
  200 groups Entra sends a pointer instead of the list and Quire grants no
  group role, so assign the application to specific groups or use app roles.
- **Okta**: use `https://<your-domain>/.well-known/openid-configuration` (or an
  `/oauth2/<server>` address for a custom authorization server), add the
  `groups` scope and a groups claim, and map the group names. The sign-in
  page preset **Okta** (under social sign-in) needs only your Okta domain,
  such as `acme.okta.com`, the client ID and the secret.
- **Google Workspace**: use `https://accounts.google.com/.well-known/openid-configuration`
  and list your domain in the connection, so an account at another domain
  is not signed in.

## SAML 2.0 <!--quire:saml-2-0-->

SAML single sign-on is part of the Business plan and above (see
[plan and billing](/admin/plans/)). On a plan without it you cannot add a
connection. If a plan later loses it, an existing connection stays readable but is
left out of the sign-in methods, so plan for another way in before you downgrade.

1. In Quire, choose **Add SAML 2.0**. Give your identity provider Quire's
   details:
   - **Metadata**: `https://<organisation>.quirelms.com/api/auth/sso/saml2/sp/metadata`
   - **Assertion consumer service (ACS)**:
     `https://<organisation>.quirelms.com/api/auth/sso/saml2/sp/acs/<connection>`
2. From your identity provider, give Quire its metadata address, or paste
   its metadata XML, or enter its sign-in address and signing certificate.
3. Send the email address as the name ID, and the given name and family name
   as attributes.

   **Microsoft Entra ID** sends the email as
   `http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress`, the
   name as `http://schemas.microsoft.com/identity/claims/displayname` and
   groups as `http://schemas.microsoft.com/ws/2008/06/identity/claims/groups`;
   enter those names as the attribute mapping. **Okta** sends whatever
   attribute statements you define; use `email`, `displayName` and a `groups`
   group attribute statement. Either name ID format works, because Quire reads
   the email from the attribute.

## Testing <!--quire:testing-->

Sign in from a private browser window with a test account before telling
everyone. Keep one administrator who can sign in with a password until single
sign-on is proven, so a misconfiguration cannot lock everyone out.

## Provisioning with SCIM <!--quire:provisioning-with-scim-->

SCIM 2.0 lets your directory create, update and suspend Quire users, and
manage group membership, without anyone uploading a spreadsheet.

1. At `/admin/security/auth`, under **User provisioning (SCIM)**, create a
   token. It is shown once.
2. In your identity provider's provisioning settings, set the SCIM base
   address to `https://<organisation>.quirelms.com/scim/v2` and the token as a
   bearer token.
3. Assign users and groups to the application.

Removing someone in the directory suspends them in Quire rather than
deleting them, so their grades and certificates are kept. Every change SCIM
makes is in the audit log under the token's name.

## LDAP <!--quire:ldap-->

For an on-premises directory without SAML or OpenID Connect, add a **LDAP
directory** connection with the server address, a bind account, and the
base under which users are found. People then sign in with their directory
password, which Quire checks against the directory and never stores.

Source: https://docs.quirelms.com/integrations/sso/index.mdx
