Firezone supports Single Sign-On (SSO) using OneLogin through the generic OIDC connector. This guide will walk you through how to obtain the following config settings required for the integration:
- Config ID: The provider's config ID. (e.g.
- Label: The button label text that shows up on your Firezone login screen. (e.g.
- Scope: OIDC scopes
to obtain from your OIDC provider. This should be set to
openid email profileto provide Firezone with the user's email in the returned claims.
- Response type: Set to
- Client ID: The client ID of the application.
- Client secret: The client secret of the application.
- Discovery Document URI: The OpenID Connect provider configuration URI which returns a JSON document used to construct subsequent requests to this OIDC provider.
Obtain Config Settings
Step 1 - Configure Custom Connector
Create a new OIDC connector by visiting Appliances > Custom Connectors.
- App name:
- Icon: Firezone logo or Firezone icon (save link as).
- Sign on method: select OpenID Connect
- Redirect URI: Add your Firezone
<EXTERNAL_URL> + /auth/oidc/<Config ID>/callback/(e.g.
Step 2 - Configure the OIDC Application
Next, click Add App to Connector to create an OIDC application. Visit the SSO tab, then change the token endpoint authentication method to POST.
You will find the values for the config settings required by Firezone on this page as well.
Integrate With Firezone
Navigate to the
/settings/security page in the admin portal, click
"Add OpenID Connect Provider" and enter the details you obtained in the steps
Enable or disable the Auto create users option to automatically create an unprivileged user when signing in via this authentication mechanism.
And that's it! The configuration should be updated immediately.
You should now see a
Sign in with OneLogin button on the sign in page.