Other providers & OpenID Connect
Twelfth works with any identity provider that speaks SAML 2.0 or OpenID
Connect — JumpCloud, OneLogin, Ping, Keycloak, Auth0 and others. Read
Single sign-on & SCIM first for how the panel
flows.
SAML 2.0
Create a SAML application in your IdP with:
| Your IdP’s field (names vary) | Twelfth value |
|---|---|
| SP Entity ID / Audience / Issuer | Identifier (Entity ID) from the panel |
| ACS URL / Reply URL / SSO URL | Reply URL (Assertion Consumer Service) from the panel |
| NameID format | urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress |
| NameID value | the person’s work email |
| Binding | HTTP-POST for the assertion; HTTP-Redirect for the request |
| Signing | Sign the assertion (Twelfth requires signed assertions) |
Send these attributes, named exactly like this:
| Attribute | Value |
|---|---|
email |
work email |
firstName |
given name |
lastName |
family name |
displayName |
full name (optional, used when first/last are absent) |
Then in Twelfth’s panel choose SAML 2.0, enter the email domain, paste your
IdP’s metadata URL or XML, and register. If your metadata has no
SingleSignOnService element, the panel will ask for the IdP’s login URL as well.
Twelfth’s own SP metadata is available at the metadata URL shown in the panel
for IdPs that want to import it.
OpenID Connect
Create an OIDC web application (authorization code flow with PKCE) with the
Redirect URI shown as OIDC redirect URI in the panel. Then in the panel
choose OpenID Connect and enter:
| Field | Value |
|---|---|
| Issuer | your IdP’s issuer URL — Twelfth reads <issuer>/.well-known/openid-configuration |
| Client ID | from the application |
| Client secret | from the application |
Twelfth requests the openid, email and profile scopes and reads the
standard email, email_verified and name claims.
Domain verification
Whatever the provider, sign-in through it stays off until the DNS TXT
record shown in the panel resolves. Press Check now once it’s added.
Provisioning
Any directory that provisions to custom SCIM 2.0 apps can manage membership.
Use the Tenant URL and a token from Generate SCIM token with bearer
(HTTP header) authentication; /Users and /Groups with filter, PATCH and
DELETE are supported, and userName should be the work email.