Get started
Request access
Ask the SSO team to register your organization and application.
There is no self-service registration yet: the SSO team registers your organization and application for you. A signed-in request form is planned.
How to ask
Email developer@aldelo.com with the details below. We confirm what we registered and send you your client_id.
Never email secrets
Don't send passwords, client secrets, tokens or private keys by email, and don't answer anyone who asks you for one. If your app needs a client secret, we agree a secure way to hand it over.
What to prepare
- Your organization. Its name, and whether it already uses Aldelo Cloud. If your app serves many organizations, say so: that needs a multi-organization registration, which is fixed when the app is registered. See Organizations.
- Your application. The name people should see when they sign in, and a technical contact.
- Application type. A server-side app that can keep a secret, or a browser or mobile app that can't. The second kind is registered as a public client and uses PKCE alone.
- Redirect URIs. Every exact URI SSO may send people back to, for example
https://app.example.com/callback. Each must use HTTPS; ask us if you need anhttp://localhostURI for local development. Include the page people land on after signing out: it is registered as one of your redirect URIs. - Scopes. Which of
email,openid,profileyou need.openidis needed for an ID token. - Back-channel logout URI (recommended). An HTTPS endpoint on your server that receives logout tokens. See Sessions and logout.
- Token lifetimes, only if the default of 600 seconds doesn't suit you.
What you receive
- Your
client_id, for exampleexample-app. - For a server-side app, a client secret, handed over securely. It is shown only once, so store it in your secret manager straight away.
- Confirmation of your registered redirect URIs, scopes and organization mode.