Skip to content
Developer docs
Menu

Get started

Request access

Ask the SSO team to register your organization and application.

There is no self-service registration yet: the SSO team registers your organization and application for you. A signed-in request form is planned.

How to ask

Email developer@aldelo.com with the details below. We confirm what we registered and send you your client_id.

Never email secrets

Don't send passwords, client secrets, tokens or private keys by email, and don't answer anyone who asks you for one. If your app needs a client secret, we agree a secure way to hand it over.

What to prepare

  • Your organization. Its name, and whether it already uses Aldelo Cloud. If your app serves many organizations, say so: that needs a multi-organization registration, which is fixed when the app is registered. See Organizations.
  • Your application. The name people should see when they sign in, and a technical contact.
  • Application type. A server-side app that can keep a secret, or a browser or mobile app that can't. The second kind is registered as a public client and uses PKCE alone.
  • Redirect URIs. Every exact URI SSO may send people back to, for example https://app.example.com/callback. Each must use HTTPS; ask us if you need an http://localhost URI for local development. Include the page people land on after signing out: it is registered as one of your redirect URIs.
  • Scopes. Which of email, openid, profile you need. openid is needed for an ID token.
  • Back-channel logout URI (recommended). An HTTPS endpoint on your server that receives logout tokens. See Sessions and logout.
  • Token lifetimes, only if the default of 600 seconds doesn't suit you.

What you receive

  • Your client_id, for example example-app.
  • For a server-side app, a client secret, handed over securely. It is shown only once, so store it in your secret manager straight away.
  • Confirmation of your registered redirect URIs, scopes and organization mode.