{"id":58304,"date":"2024-01-23T12:14:12","date_gmt":"2024-01-23T06:44:12","guid":{"rendered":"https:\/\/www.tothenew.com\/blog\/?p=58304"},"modified":"2024-01-23T12:14:12","modified_gmt":"2024-01-23T06:44:12","slug":"what-is-single-sign-on-sso-and-how-does-it-work","status":"publish","type":"post","link":"https:\/\/www.tothenew.com\/blog\/what-is-single-sign-on-sso-and-how-does-it-work\/","title":{"rendered":"What is Single Sign-On (SSO) and how does it work?"},"content":{"rendered":"<p><span style=\"font-weight: 400;\">Single sign-on (SSO) is an authentication method that enables users to securely authenticate with multiple applications and websites using just one set of credentials. <\/span><span style=\"font-weight: 400;\">SSO is an authentication scheme that allows a user to <\/span><a href=\"https:\/\/en.wikipedia.org\/wiki\/Login\"><span style=\"font-weight: 400;\">log in<\/span><\/a><span style=\"font-weight: 400;\"> with a single ID to any of several related, yet independent software systems. <\/span><span style=\"font-weight: 400;\">True single sign-on allows users to log in once and access services without re-entering authentication factors.<\/span><\/p>\n<p><strong>It should not be confused with same-sign-on (Directory Server Authentication), often accomplished by using the <a href=\"https:\/\/en.wikipedia.org\/wiki\/Lightweight_Directory_Access_Protocol\">Lightweight Directory Access Protocol<\/a> (LDAP) and storing LDAP databases on (directory) servers.<\/strong><\/p>\n<p><span style=\"font-weight: 400;\">A simple version of single sign-on can be achieved over <\/span><a href=\"https:\/\/en.wikipedia.org\/wiki\/Internet_protocol_suite\"><span style=\"font-weight: 400;\">IP networks<\/span><\/a><span style=\"font-weight: 400;\"> using <\/span><a href=\"https:\/\/en.wikipedia.org\/wiki\/HTTP_cookie\"><span style=\"font-weight: 400;\">cookies<\/span><\/a>,<span style=\"font-weight: 400;\"> but only if the sites share a common DNS parent domain.<\/span><\/p>\n<p><b>Examples<\/b><span style=\"font-weight: 400;\"> &#8211; Facebook, Twitter, Instagram, etc.<\/span><\/p>\n<h2><b>How does it work?<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">When the user tries to access a different website, the new website would have to have a similar trust relationship configured with the SSO solution, and the authentication flow would follow the same steps.<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">SSO works based on a trust relationship between an application, known as the service provider, and an identity provider, like <strong>Google<\/strong>, <strong>OneLogin<\/strong>, or <strong>miniOrange<\/strong>.\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">This trust relationship is often based upon a certificate exchanged between the identity provider and the service provider.\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">This certificate can be used to sign identity information that is being sent from the identity provider to the service provider so that the service provider knows it is coming from a trusted source.\u00a0<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">In SSO, this identity data takes the form of tokens containing identifying information about the user, like a user\u2019s email address or a username.<\/span><\/li>\n<\/ul>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter size-large wp-image-60091\" src=\"\/blog\/wp-ttn-blog\/uploads\/2024\/01\/Screenshot-from-2024-01-22-11-35-50-1024x675.png\" alt=\"SSO working approch\" width=\"625\" height=\"412\" srcset=\"\/blog\/wp-ttn-blog\/uploads\/2024\/01\/Screenshot-from-2024-01-22-11-35-50-1024x675.png 1024w, \/blog\/wp-ttn-blog\/uploads\/2024\/01\/Screenshot-from-2024-01-22-11-35-50-300x198.png 300w, \/blog\/wp-ttn-blog\/uploads\/2024\/01\/Screenshot-from-2024-01-22-11-35-50-768x506.png 768w, \/blog\/wp-ttn-blog\/uploads\/2024\/01\/Screenshot-from-2024-01-22-11-35-50-624x411.png 624w, \/blog\/wp-ttn-blog\/uploads\/2024\/01\/Screenshot-from-2024-01-22-11-35-50.png 1250w\" sizes=\"(max-width: 625px) 100vw, 625px\" \/><\/p>\n<h2><b>What is SP (Service Provider) and IDP (Identity Provider)<\/b><\/h2>\n<ul>\n<li style=\"font-weight: 400;\"><b>Service Provider (SP)<\/b> <span style=\"font-weight: 400;\">is the entity providing the service, typically in the form of an application.<\/span><\/li>\n<li style=\"font-weight: 400;\"><b>Identity Provider (IdP)<\/b> <span style=\"font-weight: 400;\">is the entity providing the identities, including the ability to authenticate a user. The Identity Provider typically also contains the user profile: additional information about the user such as first name, last name, job code, phone number, address, and so on. Depending on the application, some service providers may require a very simple profile (username, email), while others may require a richer set of user data (job code, department, address, location, manager, and so on).<\/span><\/li>\n<\/ul>\n<h2><strong>Conclusion<\/strong><\/h2>\n<p>Single Sign-On authentication solves a big problem: authenticating multiple applications with a single set of credentials. If you are implementing authentication for a new application or service, consider integrating SSO from the get-go. If you have any questions, comment them in the comment section below.<\/p>\n<div class=\"ap-custom-wrapper\"><\/div><!--ap-custom-wrapper-->","protected":false},"excerpt":{"rendered":"<p>Single sign-on (SSO) is an authentication method that enables users to securely authenticate with multiple applications and websites using just one set of credentials. SSO is an authentication scheme that allows a user to log in with a single ID to any of several related, yet independent software systems. True single sign-on allows users to [&hellip;]<\/p>\n","protected":false},"author":1594,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"iawp_total_views":16},"categories":[3602,1,3109],"tags":[1221,4862,1338],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.tothenew.com\/blog\/wp-json\/wp\/v2\/posts\/58304"}],"collection":[{"href":"https:\/\/www.tothenew.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.tothenew.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.tothenew.com\/blog\/wp-json\/wp\/v2\/users\/1594"}],"replies":[{"embeddable":true,"href":"https:\/\/www.tothenew.com\/blog\/wp-json\/wp\/v2\/comments?post=58304"}],"version-history":[{"count":5,"href":"https:\/\/www.tothenew.com\/blog\/wp-json\/wp\/v2\/posts\/58304\/revisions"}],"predecessor-version":[{"id":60104,"href":"https:\/\/www.tothenew.com\/blog\/wp-json\/wp\/v2\/posts\/58304\/revisions\/60104"}],"wp:attachment":[{"href":"https:\/\/www.tothenew.com\/blog\/wp-json\/wp\/v2\/media?parent=58304"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.tothenew.com\/blog\/wp-json\/wp\/v2\/categories?post=58304"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.tothenew.com\/blog\/wp-json\/wp\/v2\/tags?post=58304"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}