Single Sign-On

Single Sign-On (SSO) lets your users reach Road with the credentials they already have, rather than a separate Road login. Road supports two standards, SAMLv2 and OpenID Connect (OIDC), and which one fits depends on who is signing in.

Two ways to use it

Corporate directory, over SAML

For a company that manages its people in a corporate directory, Road connects to that identity provider (IdP) over SAMLv2. The SAML configuration is applied to a single Account, so everyone who authenticates through the corporate IdP belongs to that Account, and the company keeps provisioning, roles and access policy in its own directory.

Customer identities and social login, over OIDC

For a business whose users authenticate against an external IdP (WSO2, Auth0, Azure AD B2C and the like), Road connects over OIDC, with each Account mapping its own IdP login to a Road user. OIDC also drives social login, so users can sign in with Google, Apple, Facebook or another OIDC provider instead of a Road password.

Provisioning on first login

Both SAML and OIDC can create a user automatically the first time they sign in, so you do not have to provision everyone up front. It is off by default and enabled per configuration.

Choosing between them

  • SAML fits corporate identity: one corporate directory, one Account, access managed centrally by the customer's administrators.
  • OIDC is the more flexible fit for customer-facing sign-in and social login, configured per Account.

Use SAML to let a company manage its employees' access to Road through its directory; use OIDC for external customers or social login. See SAML and OpenID Connect (OIDC) to set each up.