Skip to main content

SSO Using Google

This page explains how to configure Google and then configure Styra.

Google OpenID Connect Configuration

To prepare Google OpenID Connect for signing on to styra-das-id.styra.com:

  1. Sign in to the Google Developers Console at https://console.developers.google.com/start.

  2. Select an existing project or click Create Project to create a new one.

  3. From the left-hand navigation panel, click Credentials.

  4. Click Create Credentials button to open the menu, and then click OAuth client ID.

  5. For Application type, select Web application.

  6. Enter the form with the following details and click Create.

    • Name: Styra (or anything you prefer).
    • Authorized redirect URIs: https://styra-das-id.styra.com/v1/oauth2/callback.
  7. The OAuth client created window will pop up with two pieces of data, Your Client ID and Your Client Secret. You must record this information in order to configure Styra in the next section.

Styra Configuration

At this point, Google is configured and you must configure styra-das-id.styra.com.

  1. Sign in to styra-das-id.styra.com with your username and password.

  2. Go to your-workspace and click Settings >> Single Sign-On Providers, click Add OpenID Connect Provider.

  3. Enter the form with the following details:

    • Provider name: Google (or anything you prefer).
    • Issuer URL: https://accounts.google.com.
    • Client ID: Copy the Client ID value recorded in Step 6 of the previous section.
    • Client Secret: Copy the Client Secret value recorded in Step 6 of the previous section.
    • Allowed Domains: Type the allowed authentication domain(s) of your users. For example, retail.acme.com. If the identity provider supports multiple domains, only users with these domains are allowed to access the service.
    • Invited users only: If enabled, the authenticated user must have a pre-existing account in the service. If disabled, a new user account will be created just-in-time for any authenticated user, as long as the user's domain matches one of the allowed domains (and the identity provider has assigned this user to the Styra application).
    • Enabled: set it to TRUE.
  4. If you selected just-in-time provisioning for the users, you can now logout from styra-das-id.styra.com and sign-in again using Google. Google is now displayed on styra-das-id.styra.com login screen above the username and password.

Invite Users to Styra (Optional)

If you configured styra-das-id.styra.com to allow only invited users to login to the service, then you must create users on styra-das-id.styra.com. You can add or invite users through the following options:

  • Using the CLI.
  • Using the GUI.
  • Any client calling the Styra CLI API.