Other providers & OpenID Connect

Twelfth works with any identity provider that speaks SAML 2.0 or OpenID
Connect
— JumpCloud, OneLogin, Ping, Keycloak, Auth0 and others. Read
Single sign-on & SCIM first for how the panel
flows.

SAML 2.0

Create a SAML application in your IdP with:

Your IdP’s field (names vary) Twelfth value
SP Entity ID / Audience / Issuer Identifier (Entity ID) from the panel
ACS URL / Reply URL / SSO URL Reply URL (Assertion Consumer Service) from the panel
NameID format urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress
NameID value the person’s work email
Binding HTTP-POST for the assertion; HTTP-Redirect for the request
Signing Sign the assertion (Twelfth requires signed assertions)

Send these attributes, named exactly like this:

Attribute Value
email work email
firstName given name
lastName family name
displayName full name (optional, used when first/last are absent)

Then in Twelfth’s panel choose SAML 2.0, enter the email domain, paste your
IdP’s metadata URL or XML, and register. If your metadata has no
SingleSignOnService element, the panel will ask for the IdP’s login URL as well.

Twelfth’s own SP metadata is available at the metadata URL shown in the panel
for IdPs that want to import it.

OpenID Connect

Create an OIDC web application (authorization code flow with PKCE) with the
Redirect URI shown as OIDC redirect URI in the panel. Then in the panel
choose OpenID Connect and enter:

Field Value
Issuer your IdP’s issuer URL — Twelfth reads <issuer>/.well-known/openid-configuration
Client ID from the application
Client secret from the application

Twelfth requests the openid, email and profile scopes and reads the
standard email, email_verified and name claims.

Domain verification

Whatever the provider, sign-in through it stays off until the DNS TXT
record shown in the panel resolves. Press Check now once it’s added.

Provisioning

Any directory that provisions to custom SCIM 2.0 apps can manage membership.
Use the Tenant URL and a token from Generate SCIM token with bearer
(HTTP header) authentication; /Users and /Groups with filter, PATCH and
DELETE are supported, and userName should be the work email.