Administration
Single-Sign On (SSO)
Configure OpenID Connect single sign-on for CraftedSignal, including Microsoft Entra ID setup, callback URLs, scopes, auto-provisioning, and SSO enforcement.
#Overview
CraftedSignal supports OpenID Connect (OIDC) single sign-on for organization login. Admins configure SSO in the CraftedSignal web UI, then register CraftedSignal as a confidential web application in the identity provider.
Users can start SSO from the CraftedSignal login page by entering an email address. CraftedSignal matches the email domain to the configured organization and redirects the user to the provider. CraftedSignal also exposes an IdP-initiated SSO URL for provider app tiles.
#Before you start
You need:
- Admin access in CraftedSignal.
- Application administrator access in your identity provider.
- The public HTTPS URL users use to reach CraftedSignal.
- The email domain or domains that should use this SSO configuration.
The examples below use craftedsignal.io. For self-hosted or on-prem deployments, replace craftedsignal.io with the browser-visible host configured in http.public_url. CraftedSignal builds the OIDC callback URL from this value.
http:
public_url: "https://craftedsignal.example.com"
If you explicitly configure http.trusted_origins, include the same public origin so OIDC callbacks and authenticated form submissions pass origin checks.
#Provider values
Configure the identity provider with these CraftedSignal values:
| Value | Use |
|---|---|
| Callback URL | https://craftedsignal.io/auth/oidc/callback. Add this as a web redirect URI in the provider. For on-prem, use your own public host. |
| IdP-initiated SSO URL | https://craftedsignal.io/auth/oidc/launch/<launch-id>. Optional. The launch ID is generated by CraftedSignal for your organization and appears in the SSO settings screen. Use the full displayed URL for an IdP portal tile or app dashboard link. For on-prem, use your own public host. |
| Scopes | openid email profile. |
The callback URL and IdP-initiated SSO URL are shown in Settings > Single Sign-On (SSO) after SSO settings load. Copy the IdP-initiated URL from CraftedSignal rather than inventing the launch ID.
#Generic OIDC setup
- Create a new OIDC web application in your identity provider.
- Add the CraftedSignal callback URL as a web redirect URI.
- Use the Authorization Code flow. Do not enable implicit grant for new applications.
- Allow the
openid,email, andprofilescopes. - Create a client secret for the application.
- Copy the provider issuer URL, client ID, and client secret into CraftedSignal.
- Save the SSO settings and run the SSO test.
- Enable auto-provisioning only if new SSO users should be created automatically.
- Enforce SSO only after an admin has completed a successful SSO login.
CraftedSignal stores the client secret encrypted. If the secret expires or is rotated in the provider, update the CraftedSignal SSO settings before the old secret stops working.
#Microsoft Entra ID
Use a custom app registration for Microsoft Entra ID. This follows Microsoft’s OIDC SSO setup flow for custom non-gallery applications .
#1. Register the application
- Open the Microsoft Entra admin center.
- Go to Entra ID > App registrations > New registration.
- Name the application, for example
CraftedSignal. - For most organizations, select Accounts in this organizational directory only.
- Under Redirect URI, choose Web and enter:
https://craftedsignal.io/auth/oidc/callback
- Select Register.
#2. Create a client secret
- In the app registration, go to Certificates & secrets.
- Select New client secret.
- Choose an expiration period that matches your rotation policy.
- Copy the secret value immediately. Entra does not show the value again.
Use the secret value in CraftedSignal, not the secret ID.
#3. Check permissions
In API permissions, make sure the application can request the basic OIDC delegated scopes:
openidemailprofile
Grant admin consent if your tenant policy requires it.
If user email is not present in ID tokens, add an optional email claim under Token configuration or confirm that your users have a populated mail/user principal value that Entra releases to the application.
#4. Copy values into CraftedSignal
In CraftedSignal, open Settings > Single Sign-On (SSO) and set:
| CraftedSignal field | Microsoft Entra value |
|---|---|
| Issuer URL | https://login.microsoftonline.com/<tenant-id>/v2.0 |
| Client ID | Application (client) ID from the app registration overview. |
| Client Secret | Client secret value from Certificates & secrets. |
| Scopes | openid email profile |
| Email domains | Your login domains, for example example.com or example.com, example.org. Do not include @. |
The Entra OIDC metadata document for a tenant is:
https://login.microsoftonline.com/<tenant-id>/v2.0/.well-known/openid_configuration
#5. Assign users
If assignment is required for the enterprise application, go to Enterprise applications, open the CraftedSignal application, and assign the users or groups that should be able to sign in.
For a Microsoft Entra portal tile, use the IdP-initiated SSO URL from CraftedSignal as the application home or launch URL.
#CraftedSignal settings
| Setting | Guidance |
|---|---|
| Issuer URL | The OIDC issuer or authority URL. For Entra, use the tenant-specific https://login.microsoftonline.com/<tenant-id>/v2.0 value. |
| Client ID | The OIDC application client ID. |
| Client Secret | The confidential client secret. Leave blank on later edits unless rotating the secret. |
| Email domains | Comma-separated domains used to route login attempts to this organization. Domains must be unique across organizations. |
| Enforce SSO | Blocks password login for matching SSO users. Enable only after a successful test login. |
| Auto-provision | Creates new users on first SSO login. |
| Default role | Role assigned to auto-provisioned users. Use Viewer unless new users should immediately create or edit detection content. |
#Troubleshooting
| Symptom | Check |
|---|---|
OIDC discovery failed | Issuer URL is reachable over HTTPS and points to the tenant-specific OIDC issuer. For Entra, use the /v2.0 issuer. |
redirect_uri mismatch | The provider redirect URI exactly matches https://craftedsignal.io/auth/oidc/callback, including scheme, host, and path. For on-prem, compare against your own public host instead. |
OIDC not configured this email domain | The user’s email domain is listed in CraftedSignal without @, and SSO is enabled for the organization. |
| User cannot sign in after secret rotation | Update the client secret in CraftedSignal with the new secret value. |
| Email missing from token | Add or release an email claim in the provider, or verify the user’s mail attribute is populated. |
Keep at least one tested admin access path while rolling out SSO enforcement.