Single Sign On (SSO) allows your team to log in to IBM Digital Asset Haven using your existing identity provider. This enhances security by centralizing user authentication and management. IBM Digital Asset Haven SSO supports all OpenID Connect (OIDC) providers. You can configure your organization to use SSO and automatically redirect users when they log in to IBM Digital Asset Haven.
Before you begin
Ensure you have access to:
- Your IBM Digital Asset Haven account with sufficient permissions.
- Your organization’s identity provider (for example, Okta, Entra, or Google Workspace) with sufficient permissions.
Procedure
-
Initiate SSO Configuration in IBM Digital Asset Haven
-
Log in to the IBM Digital Asset Haven dashboard and navigate to Settings > SSO.
-
Select Activate SSO for this organization.
-
Copy the Redirect URL. You will need this to configure your identity provider.
If you are building another frontend for customers, you can add their redirect URLs here.
-
Configure Your Identity Provider
Set up an application in your identity provider’s dashboard. Instructions for detailed tutorials for some common providers are provided below:
-
Okta: Step-by-step tutorial
-
Entra ID (formerly Azure AD): Step-by-step tutorial
-
Google Workspace: Step-by-step tutorial
Each tutorial covers registering an application, configuring redirect URIs, and obtaining client credentials (Client ID and Client Secret).
-
Finalize SSO Configuration in IBM Digital Asset Haven
-
Return to the SSO configuration page in IBM Digital Asset Haven.
-
Enter the following information from your identity provider:
OpenID Configuration URL: configuration URL (for Okta and Entra ID) or issuer URL (for other OIDC providers)
Client ID
Client Secret
-
Click Save.
-
Invite Users with SSO
-
Go to the Users page.
-
Select Invite a new user.
-
In the form, check Require SSO to enforce login through SSO.
-
Require SSO for Existing Users
-
Go to the Users page.
-
Open the menu for a user and enable Require SSO.
This step requires the Auth:Users:Update permission.
-
Log Users in Through SSO
Once SSO is enabled, users will be redirected to your identity provider login page:
-
Default IBM Digital Asset Haven dashboard login : Users sign in with their passkey, and then are redirected to SSO.
-
Direct SSO URL: Users log in directly and are redirected to the IBM Digital Asset Haven dashboard.
-
IBM Digital Asset Haven SSO redirection URL: Users are redirected to SSO automatically, without using a passkey.
Results
Your SSO integration is now complete. Team members can log in to IBM Digital Asset Haven using their identity provider credentials.
If you encounter issues, contact IBM Digital Asset Haven Support.