PageSourceSearch

https://authress.io/knowledge-base/assets/js/47706d75.95b853f4.js

js authress.io collected 2026-09-24 18:30:54 UTC 10,494 bytes, 1 lines download raw bytes

1"use strict";(self.webpackChunkAuthressKnowledgeBase=self.webpackChunkAuthressKnowledgeBase||[]).push([[4871],{3905:(e,t,n)=>{n.d(t,{Zo:()=>c,kt:()=>d});var a=n(67294);function o(e,t,n){return t in e?Object.defineProperty(e,t,{value:n,enumerable:!0,configurable:!0,writable:!0}):e[t]=n,e}function i(e,t){var n=Object.keys(e);if(Object.getOwnPropertySymbols){var a=Object.getOwnPropertySymbols(e);t&&(a=a.filter((function(t){return Object.getOwnPropertyDescriptor(e,t).enumerable}))),n.push.apply(n,a)}return n}function r(e){for(var t=1;t<arguments.length;t++){var n=null!=arguments[t]?arguments[t]:{};t%2?i(Object(n),!0).forEach((function(t){o(e,t,n[t])})):Object.getOwnPropertyDescriptors?Object.defineProperties(e,Object.getOwnPropertyDescriptors(n)):i(Object(n)).forEach((function(t){Object.defineProperty(e,t,Object.getOwnPropertyDescriptor(n,t))}))}return e}function s(e,t){if(null==e)return{};var n,a,o=function(e,t){if(null==e)return{};var n,a,o={},i=Object.keys(e);for(a=0;a<i.length;a++)n=i[a],t.indexOf(n)>=0||(o[n]=e[n]);return o}(e,t);if(Object.getOwnPropertySymbols){var i=Object.getOwnPropertySymbols(e);for(a=0;a<i.length;a++)n=i[a],t.indexOf(n)>=0||Object.prototype.propertyIsEnumerable.call(e,n)&&(o[n]=e[n])}return o}var l=a.createContext({}),p=function(e){var t=a.useContext(l),n=t;return e&&(n="function"==typeof e?e(t):r(r({},t),e)),n},c=function(e){var t=p(e.components);return a.createElement(l.Provider,{value:t},e.children)},u={inlineCode:"code",wrapper:function(e){var t=e.children;return a.createElement(a.Fragment,{},t)}},h=a.forwardRef((function(e,t){var n=e.components,o=e.mdxType,i=e.originalType,l=e.parentName,c=s(e,["components","mdxType","originalType","parentName"]),h=p(n),d=o,g=h["".concat(l,".").concat(d)]||h[d]||u[d]||i;return n?a.createElement(g,r(r({ref:t},c),{},{components:n})):a.createElement(g,r({ref:t},c))}));function d(e,t){var n=arguments,o=t&&t.mdxType;if("string"==typeof e||o){var i=n.length,r=new Array(i);r[0]=h;var s={};for(var l in t)hasOwnProperty.call(t,l)&&(s[l]=t[l]);s.originalType=e,s.mdxType="string"==typeof e?e:o,r[1]=s;for(var p=2;p<i;p++)r[p]=n[p];return a.createElement.apply(null,r)}return a.createElement.apply(null,n)}h.displayName="MDXCreateElement"},54318:(e,t,n)=>{n.r(t),n.d(t,{assets:()=>l,contentTitle:()=>r,default:()=>u,frontMatter:()=>i,metadata:()=>s,toc:()=>p});var a=n(87462),o=(n(67294),n(3905));
1const i={sidebar_label:"AWS",title:"AWS Single Sign-On",description:"Login to Authress using AWS SSO",image_alt:"AWS SSO integration",category:"Technical help",date:"2022-09-28T10:00"},r=void 0,s={unversionedId:"account-management/sso/aws-sso",id:"account-management/sso/aws-sso",title:"AWS Single Sign-On",description:"Login to Authress using AWS SSO",source:"@site/docs/70-account-management/00-sso/01-aws-sso.md",sourceDirName:"70-account-management/00-sso",slug:"/account-management/sso/aws-sso",permalink:"/knowledge-base/docs/account-management/sso/aws-sso",draft:!1,editUrl:"https://gitlab.com/rhosys/authress-public-kb/knowledge-base/-/blob/main/docs/70-account-management/00-sso/01-aws-sso.md",tags:[],version:"current",lastUpdatedAt:1772377859,formattedLastUpdatedAt:"Mar 1, 2026",sidebarPosition:1,frontMatter:{sidebar_label:"AWS",title:"AWS Single Sign-On",description:"Login to Authress using AWS SSO",image_alt:"AWS SSO integration",category:"Technical help",date:"2022-09-28T10:00"},sidebar:"tutorialSidebar",previous:{title:"Admin SSO",permalink:"/knowledge-base/docs/account-management/sso/"},next:{title:"Okta",permalink:"/knowledge-base/docs/account-management/sso/okta-configuration"}},l={},p=[{value:"Create the Authress App in the AWS Application Portal",id:"create-the-authress-app-in-the-aws-application-portal",level:2},{value:"Configure the Authress Service Provider",id:"configure-the-authress-service-provider",level:2},{value:"Easy login",id:"easy-login",level:2},{value:"Configure the AWS application",id:"configure-the-aws-application",level:2},{value:"Complete the AWS application configuration",id:"complete-the-aws-application-configuration",level:2},{value:"Finishing up",id:"finishing-up",level:2},{value:"Troubleshooting",id:"troubleshooting",level:2}],c={toc:p};
1function u(e){let{components:t,...i}=e;return(0,o.kt)("wrapper",(0,a.Z)({},c,i,{components:t,mdxType:"MDXLayout"}),(0,o.kt)("p",null,"This article explains the process to connect AWS SSO Identity Center and SSO applications in your AWS account to Authress. This allows your engineers to log into Authress using your AWS account."),(0,o.kt)("p",null,"The SSO Application configuration is located in ",(0,o.kt)("a",{parentName:"p",href:"https://console.aws.amazon.com/singlesignon/applications/home#"},"AWS IAM Identity Center"),"."),(0,o.kt)("h2",{id:"create-the-authress-app-in-the-aws-application-portal"},"Create the Authress App in the AWS Application Portal"),(0,o.kt)("p",null,"AWS supports the SAML flow, so navigate to the ",(0,o.kt)("a",{parentName:"p",href:"https://console.aws.amazon.com/singlesignon/applications/home#/add"},"Portal")," and a new application. Review the SAML metadata fields and download the ",(0,o.kt)("strong",{parentName:"p"},"IAM Identity Center Certificate"),":"),(0,o.kt)("p",null,(0,o.kt)("img",{alt:"Authress SAML configuration",src:n(89370).Z,width:"932",height:"436"})),(0,o.kt)("h2",{id:"configure-the-authress-service-provider"},"Configure the Authress Service Provider"),(0,o.kt)("p",null,"Open the ",(0,o.kt)("a",{parentName:"p",href:"https://authress.io/app/#/setup?focus=general&tab=sso"},"Authress management portal")," to the ",(0,o.kt)("inlineCode",{parentName:"p"},"Single Sign-On")," options and select ",(0,o.kt)("strong",{parentName:"p"},"SAML connection")," as the ",(0,o.kt)("strong",{parentName:"p"},"User Management Provider"),". We'll then fill out of the fields that can be found in the AWS application portal:"),(0,o.kt)("ul",null,(0,o.kt)("li",{parentName:"ul"},"In the ",(0,o.kt)("inlineCode",{parentName:"li"},"SSO Url")," property enter the ",(0,o.kt)("inlineCode",{parentName:"li"},"IAM Identity Center sign-in URL")," from AWS."),(0,o.kt)("li",{parentName:"ul"},"In the ",(0,o.kt)("inlineCode",{parentName:"li"},"Entity ID")," property enter the ",(0,o.kt)("inlineCode",{parentName:"li"},"IAM Identity Center SAML issuer URL")," from AWS."),(0,o.kt)("li",{parentName:"ul"},"Then open the downloaded certificate and paste the contents into the field in Authress.")),(0,o.kt)("p",null,(0,o.kt)("img",{alt:"Authress SAML configuration",src:n(49471).Z,width:"1118",height:"885"})),(0,o.kt)("h2",{id:"easy-login"},"Easy login"),(0,o.kt)("p",null,"To allow automated login through AWS, you'll want to choose an ",(0,o.kt)("strong",{parentName:"p"},"Authress account SSO domain"),". This domain is part of the ",(0,o.kt)("inlineCode",{parentName:"p"},"SAML Start URL")," configuration in AWS and makes it easy to directly log in. This field can be anything not already chosen by another account, but we recommend your corporate domain:"),(0,o.kt)("p",null,(0,o.kt)("img",{alt:"Authress SAML configuration",src:n(76093).Z,width:"788",height:"176"})),(0,o.kt)("h2",{id:"configure-the-aws-application"},"Configure the AWS application"),(0,o.kt)("p",null,"Next complete the Authress setup by copying the three Authress SAML values back to AWS. It is important that these three values exactly match the ones found in the Authress Management Portal:"),(0,o.kt)("p",null,(0,o.kt)("img",{alt:"AWS SSO application configuration",src:n(19738).Z,width:"1214",height:"663"})),(0,o.kt)("h2",{id:"complete-the-aws-application-configuration"},"Complete the AWS application configuration"),(0,o.kt)("p",null,"There is one more step that is required for the application configuration. Edit the application attributes:"),(0,o.kt)("p",null,(0,o.kt)("img",{alt:"AWS SSO application attributes",src:n(82004).Z,width:"813",height:"352"})),(0,o.kt)("p",null,"And set the empty mapping for ",(0,o.kt)("inlineCode",{parentName:"p"},"Subject")," to have the value ",(0,o.kt)("inlineCode",{parentName:"p"},"${user:email}")),(0,o.kt)("p",null,(0,o.kt)("img",{alt:"AWS SSO application attributes for subject",src:n(95369).Z,width:"1029",height:"430"})),(0,o.kt)("h2",{id:"finishing-up"},"Finishing up"),(0,o.kt)("p",null,"In Authress there is one more step, and that is to select your SSO quick domain. This domain should be your corporate domain and makes it easy and fast to login to Authress. This domain al
1so is part of your ",(0,o.kt)("inlineCode",{parentName:"p"},"Start URL")," so"),(0,o.kt)("p",null,"Now save both your AWS SAML application, and the Authress configuration, and you are done. To test out your new connection navigate to, to your AWS application portal and select the new SAML app from the dashboard or navigate to the ",(0,o.kt)("a",{parentName:"p",href:"https://authress.io/app/#/sso"},"Authress SSO Login screen")," and specify the ",(0,o.kt)("inlineCode",{parentName:"p"},"AWS corporate domain")," value you entered earlier into your configuration."),(0,o.kt)("h2",{id:"troubleshooting"},"Troubleshooting"),(0,o.kt)("p",null,"In the event you a ",(0,o.kt)("inlineCode",{parentName:"p"},"403")," or a ",(0,o.kt)("inlineCode",{parentName:"p"},"404")," from AWS upon logging in, update your AWS application configuration. This error means that the attribute configuration must be updated. Review the ",(0,o.kt)("a",{parentName:"p",href:"#complete-the-aws-application-configuration"},"above sections")," for the expected attribute mapping in AWS:"),(0,o.kt)("p",null,(0,o.kt)("img",{alt:"AWS SSO application error",src:n(41785).Z,width:"1099",height:"266"})))}u.isMDXComponent=!0},19738:(e,t,n)=>{n.d(t,{Z:()=>a});const a=n.p+"assets/images/aws-saml-application-configuration-74b87d220389bfe7ac964465f5142d8d.png"},49471:(e,t,n)=>{n.d(t,{Z:()=>a});const a=n.p+"assets/images/aws-saml-authress-configuration-e1743dff38eb95b549a07aeab5c93372.png"},95369:(e,t,n)=>{n.d(t,{Z:()=>a});const a=n.p+"assets/images/aws-saml-edit-attributes-subject-b2a7c979ff9941af1172592dfdc157de.png"},82004:(e,t,n)=>{n.d(t,{Z:()=>a});const a=n.p+"assets/images/aws-saml-edit-attributes-ece98ec428c9d50f5982a2a752056f0f.png"},41785:(e,t,n)=>{n.d(t,{Z:()=>a});const a=n.p+"assets/images/aws-saml-sso-application-403-bc2237a740d1de395fc7248ab7bab45d.png"},89370:(e,t,n)=>{n.d(t,{Z:()=>a});const a=n.p+"assets/images/aws-saml-sso-2dda4054fc7e30288290cfaae7959f72.png"},76093:(e,t,n)=>{n.d(t,{Z:()=>a});const a=n.p+"assets/images/corporate-domain-2cd92e64808b1f318e46c0a3c5fe9555.png"}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.