Skip to main content
Open Settings > Single sign-on to view identity providers. A role with view permission can inspect providers. A role with SSO management permission can create, edit, enable, disable, and delete them.

Choose a protocol

Configure SAML

Exchange service-provider values and SAML metadata.

Configure OIDC

Register a callback and configure issuer discovery.

Configuration flow

1

Start in K16

Select New identity provider and choose SAML or OIDC.
2

Copy service-provider values

Use the values shown in Service provider values to configure the application in your identity provider.
3

Enter identity-provider values

Return to K16 and complete the protocol-specific fields.
4

Create the provider

Keep Enabled for sign-in on only when you are ready to test, then select Create.
5

Test with a pilot user

Assign a test user in the identity provider and use the normal K16 sign-in flow. Keep the current administrator session open until the test succeeds.
Provider names must be at least three characters and cannot contain spaces or underscores. The protocol and provider name cannot be changed after creation. Create a replacement provider when either must change.
Do not delete a working provider until its replacement has passed sign-in and sign-out testing. Provider changes can take several minutes to appear.
See Troubleshoot SSO when sign-in fails.
Last modified on September 16, 2026