> For the complete documentation index, see [llms.txt](https://fredhopper.gitbook.io/product-discovery/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://fredhopper.gitbook.io/product-discovery/fhr-merchandising-studio-sso-setup/sso-technical-reference.md).

# SSO Technical Reference

This page provides technical details about Fredhopper's SSO implementation for IT and security teams evaluating identity provider compatibility or completing vendor security questionnaires. Fredhopper has been successfully integrated with Microsoft Entra ID (Azure AD).

{% hint style="info" %}
For step-by-step setup instructions see [Configuring Microsoft Entra ID for SSO access](/product-discovery/fhr-merchandising-studio-sso-setup/configuring-microsoft-entra-id-for-sso-access.md).
{% endhint %}

{% hint style="info" %}
If you are using a different identity provider, reach out to [Customer Support](https://support.rezolve.com/hc/en-us) to discuss compatibility.
{% endhint %}

## Supported protocols

Fredhopper supports both OIDC and SAML 2.0 for SSO authentication. OIDC has been validated in production environments. SAML 2.0 is supported via the underlying Keycloak platform but hasn't yet been validated in our environment. If you'd like to use SAML, we're happy to arrange testing in a test environment before go-live in production.

{% hint style="info" %}
Encrypted assertions and encrypted name identifiers are not required for either protocol.
{% endhint %}

## OIDC configuration

Fredhopper uses the Authorization Code Grant type for OIDC flows. Users are identified by their email address. No additional attributes are required, though given name and last name are accepted and stored if provided by your identity provider.

SP-initiated initiated SSO is supported. Fredhopper sends an authentication request to your identity provider, and deep linking is supported because the SP-initiated flow preserves the originally requested URL and returns the user there after authentication.

## SAML configuration

For SAML integrations, Fredhopper supports Post binding. The following name identifier formats are supported: Persistent, Transient, Email Address, and Unspecified.

## User roles and access

Role assignment is *not* driven by IDP group claims. When users authenticate via SSO for the first time, they're assigned a default read-only role within the application. A Merchandising Studio admin can then grant additional roles directly within the application.

{% hint style="info" %}
If a user previously had local access, their permissions are reset to the default role upon first SSO login.
{% endhint %}

## **User provisioning**

Out-of-band user provisioning, including SCIM, isn't currently offered. Users are provisioned automatically on first SSO login based on their identity provider credentials.

## **Testing environments**

Test environments are available for validating your SSO integration before go-live. Test environments are retained after go-live for ongoing validation and regression testing.
