Skip to main content

Enabling Single Sign On (Pyn 2)

How to set up SSO in Pyn with Okta or an OIDC provider

M
Written by Matt Sutton

Before you start

Pyn supports SSO logins with Okta or a custom OIDC provider. SAML2.0 is available with Okta, and OpenID Connect is available for other providers.

Setting up Okta SSO

Instructions on setting up Okta SSO are available at https://intercom.help/pyn/en/articles/16838252-connect-to-okta-sso-pyn-2

Setting up OpenID Connect

Required provider-side configuration

Set up with your provider will vary between providers. You'll find detailed set up instructions in the provider's documentation. The details specifically for Pyn are as follows:

Required claims: openid, profile, email

Optional claims: groups or roles (this contains the groups claims from your IDP for role mapping)

The details you'll need from your OIDC provider to set up SSO with Pyn are:

  • Issuer URL: for Keycloak users, this is split between the Server URL and the Realm

  • Client ID

  • Client Secret

  • Groups Claim: this is often groups, but Entra users this will be roles

Role mapping

Pyn has the following roles available, each inheriting from the roles beneath:

  • Owner is the highest role in Pyn. Owners can assign and modify other Owners

  • Admin has full access to settings, integrations, directory, user invites, and role assignment (except for Owners)

  • Power User can create and publish Flows and view form submissions

  • User has read access to content, journeys, and activity. A user can pause and unpause enrollments and messages

When mapping roles between your IDP and Pyn, keep in mind that Pyn will select the highest role for a user when provided multiple roles.

Configuring Pyn

Navigate to Settings -> Integrations -> Available. Press the Single Sign-On tile.

In the Connect single sign-on dialog, enter in the following:

  • Provider: Pyn supports Keycloak, Okta, Entra, Auth0, Ping Identify, and Custom

  • Issuer URL: (this will be Keycloak Server URL and Realm for Keyloak users)

  • Client ID and Client Secret: from the provider-side step above

  • Groups Claim: the name of the groups claim from your IDP. Left blank, defaults to groups

Press Connect. On success, you'll see the integration appear under Installed, and the integration panel open.

Setting Group Mappings

Once the SSO integration has been set up, you can enter a comma-separated list of groups supplied by your IdP that will be associated with the Pyn groups.

Frequently asked questions

Does Pyn support JIT provisioning of new users?

No. Pyn users can be invited, disabled, and removed through the Pyn settings UI.

How long does a session last in Pyn?

A session in Pyn lasts for 24 hours by default. Reach out to Pyn support for shorter session times for your workspace. A user can log themselves out at any time by visiting: https://pyn.ai/sign-out

Can we use the same client set up for Sandbox accounts?

This is not recommended. Pyn suggests a separate IDP client set up for sandbox and production workspaces.

Did this answer your question?