OIDC Single Sign-On
Follow these instructions to integrate with Monkey using Single Sign-On.
Environments
Use the following Entity ID and Reply URL values when configuring SAML 2.0 federation in your system.
Supply Plus
Staging
Entity ID: urn:amazon:cognito:sp:us-east-1_7naoZpEQT
Reply URL: https://hmg-sso.monkeyecx.com/oauth2/idpresponse
Production
Entity ID: urn:amazon:cognito:sp:us-east-1_Gxn6sqn9J
Reply URL: https://cognito-sso.monkey.exchange/oauth2/idpresponse
Required Information
Send us the following information so that we can complete the integration setup:
Client ID: The client_id provided by your OpenID Connect identity provider.
Client Secret: The client_secret provided by your OpenID Connect identity provider.
Authorized scopes: The scopes we will use to access your users’ information during federation.
Attribute request method: The HTTP method we should use to request user information: POST or GET.
Issuer URL: The issuer URL that we can use to retrieve the authentication endpoint, token endpoint, user information endpoint, and jwks_uri values.
Email suffixes: The email suffixes of users who will use federation, such as @monkey.tech and @monkey.exchange. This enables automatic redirection to federated login.
After we receive this information, we will configure the integration on our side and notify you to run validation tests.
Advanced Configuration
In addition to platform access, you can configure detailed permissions for each user. To manage permissions through your identity provider instead of manually in the platform, include the following access-control attributes:
role: The user’s platform role. Available values are ADMIN, EXECUTE, SELECTOR, and VIEW.
governmentId: The CNPJs that the user can access, separated by commas. For example: 11024188000124,32779813000118.
We use these additional values to map each user’s access permissions to the companies registered in the platform.
Updated about 1 month ago