SAML | Connecting to Oyster

Company administrators have the ability to configure an Identity Provider to power Single Sign On (SSO). This article details how to configure an Identity Provider using the Security Assertion Markup Language (SAML) protocol to facilitate SSO with the Oyster application. You can learn more about the SAML protocol and how it works here

What's supported in the SAML and Oyster integration

  • Service Provider (SP)-Initiated Authentication (SSO) Flow - This authentication flow occurs when the user attempts to log in to the application from Oyster HR.

Who are the identity providers using OIDC?

Here are some of the identity providers you can connect using OIDC:

  • Amazon Web Services (AWS)
  • Oracle Identity Cloud Service
  • SAP Identity Authentication Service
  • Centrify

Requirements

In order to proceed with configuring login with SSO through SAML, you must:

  • Be an administrator on your Identity Provider
  • Have a company administrator account on the Oyster app

Important pointers before you start the process

  1. You won’t be able to enable the integration if at least one of the customer users on your company is already using SSO with another company.
  2. Once the SAML integration is enabled, there is no way of changing the credentials used for the integration. You'll need to delete the integration and set up a new one if you need to update the credentials.
  3. SAML SSO is supported for both admin and manager roles but not supported for your team members when they log into their Oyster account. Only account admins can set up the integration.
  4. You can only “Sign in” into your existing Oyster account using this SAML SSO integration and not “Sign up”.

Steps

Follow these steps to set up an the integration between Oyster and your Identity Provider using SAML:

  1. Log in to the Oyster platform
  2. Click on Company > Integrations in the menu bar 
  3. Select the Available integrations tab
Step 3 - Available integrations.png
  1. Scroll down to the Identity Providers section and click Connect under SAML
     
Step 4 - Select SAML.png
  1. Copy the Callback URL and configure your SAML application to allow it to make callbacks to this URL. Also configure “email” attribute statement in your SAML application to be mapped to the user’s email address
  2. Select the checkbox under Permissions and click Connect
Step 5 - Callback url.png
  1. Paste in your SAML Sign In Url, upload your applications’ Signing Certificate, and click Submit
     
Step 7.png
  1. Copy the provided Audience URI parameter and configure your SAML application with it
  2. Click Close and go to Integrations
     
Step 8 - Finish SAML configuration.png

Your Identity Provider using SAML is now enabled for your users! Your eligible users will now be able to sign in using the SSO option on the sign-in page.

Was this article helpful?

0 out of 2 found this helpful