Before you start
Pyn supports SSO logins with Okta or a custom OIDC provider. SAML2.0 is available with Okta, and OpenID Connect is available for other providers.
Setting up Okta SSO
Instructions on setting up Okta SSO are available at https://intercom.help/pyn/en/articles/16838252-connect-to-okta-sso-pyn-2
Setting up OpenID Connect
Required provider-side configuration
Set up with your provider will vary between providers. You'll find detailed set up instructions in the provider's documentation. The details specifically for Pyn are as follows:
Callback URL: https://pyn.ai/api/oidc/callback
Required claims: openid, profile, email
Optional claims: groups or roles (this contains the groups claims from your IDP for role mapping)
The details you'll need from your OIDC provider to set up SSO with Pyn are:
Issuer URL: for Keycloak users, this is split between the Server URL and the Realm
Client ID
Client Secret
Groups Claim: this is often
groups, but Entra users this will beroles
Role mapping
Pyn has the following roles available, each inheriting from the roles beneath:
Owner is the highest role in Pyn. Owners can assign and modify other Owners
Admin has full access to settings, integrations, directory, user invites, and role assignment (except for Owners)
Power User can create and publish Flows and view form submissions
User has read access to content, journeys, and activity. A user can pause and unpause enrollments and messages
When mapping roles between your IDP and Pyn, keep in mind that Pyn will select the highest role for a user when provided multiple roles.
Configuring Pyn
Navigate to Settings -> Integrations -> Available. Press the Single Sign-On tile.
In the Connect single sign-on dialog, enter in the following:
Provider: Pyn supports Keycloak, Okta, Entra, Auth0, Ping Identify, and Custom
Issuer URL: (this will be Keycloak Server URL and Realm for Keyloak users)
Client ID and Client Secret: from the provider-side step above
Groups Claim: the name of the groups claim from your IDP. Left blank, defaults to
groups
Press Connect. On success, you'll see the integration appear under Installed, and the integration panel open.
Setting Group Mappings
Once the SSO integration has been set up, you can enter a comma-separated list of groups supplied by your IdP that will be associated with the Pyn groups.
Frequently asked questions
Does Pyn support JIT provisioning of new users?
No. Pyn users can be invited, disabled, and removed through the Pyn settings UI.
How long does a session last in Pyn?
A session in Pyn lasts for 24 hours by default. Reach out to Pyn support for shorter session times for your workspace. A user can log themselves out at any time by visiting: https://pyn.ai/sign-out
Can we use the same client set up for Sandbox accounts?
This is not recommended. Pyn suggests a separate IDP client set up for sandbox and production workspaces.

