SSO Configuration Guide

View as Markdown

Kumo uses Auth0 to support a variety of secure single-sign-on mechanisms to simplify user management for your team. The two easiest integrations are:

  1. Google Workspace Single Sign On
  2. OIDC - OpenID Connect - supporting many other services including Okta and Azure Active Directory

SSO configuration options in Kumo

To enable Google Workspace Single Sign On for your environment, no action is needed on your end. Contact your Kumo point of contact, and it can be enabled within hours.

The remainder of this document describes the process to set up OIDC. For illustration, Okta is used as the OIDC provider, but these instructions work with any other OIDC-compliant auth provider.

Okta Configuration

  1. Go to your Applications and create a new Application with the following settings:

    • Sign-in method: OIDC - OpenID Connect
    • Application type: Single-Page Application
  2. Under General Settings, make sure to select Grant types of Authorization Code and Implicit (Hybrid)

Okta General Settings showing Grant types

  1. Next, add the following sign-in and sign-out URLs

Okta sign-in and sign-out URL configuration

NOTE: Use auth.kumoai.cloud instead of kumoai.us.auth0.com as shown in the image above

  1. Select your preferred Assignment policy

Okta Assignment policy selection

  1. Click Save to create the app.
  2. Copy the Client ID and your Okta base URL
    • Example Client ID: 0oa654ok0jBdIJrpT5d7
    • Example Okta URL: dev-22499602.okta.com

Okta Client ID and base URL

  1. Send your Client ID and Okta Base URL to the Kumo team

You receive a notification from Kumo when your SSO onboarding is complete.