Setting up Single Sign-On (SSO) on your portal

Edited

The SSO feature is enabled on Advanced and Ultimate plans, and is otherwise available as an add-on.

Single Sign-On (SSO) lets your users authenticate to the Huwise platform using your organization’s identity provider (IdP), such as Azure AD, Google Workspace, Okta, or Auth0.

Huwise supports two authentication protocols:

  • SAML 2.0

  • OpenID Connect (OIDC) with full multi-IdP support

The SSO interface has been redesigned around a guided setup wizard, making configuration clearer, safer, and easier to maintain.

Configuring an IdP

Your IdPs are managed from a centralized view, and each identity can be activated or deactivated independently.

To set up a new identity, click on Add a provider. A wizard will open up to guide you through the process.

For each existing configuration, click on the three dot icon on the far right to edit a configuration, activate or deactivate it, or delete it.

Supported protocols

OpenID Connect (OIDC) & specialized connectors

OIDC is our recommended protocol due to its modern architecture and ease of maintenance. Huwise offers a flexible OIDC engine that includes dedicated connectors for specific ecosystems:

1. Standard OpenID Connect

  • Full Multi-OIDC support

  • Several IdPs, ID providers, can be active at the same time

  • Ideal for large organizations consolidating or migrating

See this page for more detailed instructions on using OIDC for your SSO.

2. Specialized connectors (France)

To simplify integration for French public and healthcare organizations, we have developed dedicated OIDC connectors. These modules are preconfigured to handle the specific security requirements and scopes of French national identity hubs:

  • ProConnect: A dedicated connector for French public service agents, ensuring seamless professional login.

  • Pro Santé Connect: A specialized connector for healthcare professionals, supporting strong authentication via CPS or e-CPS cards through the ANS infrastructure.

These specialized connectors are sub-types of the OpenID Connect family. They appear as distinct options in the setup wizard to provide a "plug-and-play" experience for French institutional users.

See this page for more detailed instructions on using Pro Connect or Pro Santé Connect for your SSO.

SAML 2.0

  • One active SAML provider

  • Possibility to store multiple inactive SAML configurations

  • Switching active SAML providers requires deactivating the current one

See this page for more detailed instructions on using SAML for your SSO.