GreenLine-logo-transparent.png
Find the insights and best practices about our product.
Single Sign-On (SSO)

Access

Only the Organization Owner or licensed members with the Advanced Features permission can access this area. Learn more about managing members in your organization.

  1. From the left navigation, click on your Organization (icon at the bottom)
  2. This will open the Organization panel, click Single Sign-On (SSO)

Use

OpenID Connect (OIDC) is an open authentication protocol that works on top of the OAuth 2.0 framework. OIDC allows GreenLine members to use single sign-on (SSO) to access GreenLine using an OpenID Identity Provider (IdP) to authenticate their identities.


Organizations within GreenLine can choose to enforce SSO for all members of their GreenLine organization or configure select members to bypass and login with their GreenLine email address.

What you will need

  1. An Enterprise Plan in GreenLine
  2. An OpenID Connect (OIDC) compatible Identity Provider (IdP)
  3. Your IdP Issuer Url/Base Url
  4. Your IdP Application Client ID
  5. The GreenLine redirect URI – https://greenline.works/login/sso/complete
    1. This is used within your IdP application setup when prompted for a redirect URI
  6. Access to the GreenLine SSO Organization Configuration
    1. The Organization Owner of GreenLine will have access
    2. Any GreenLine member with Security Permissions will have access, for more information on permissions, see our manage members article

IdP Setup and Configuration

  1. Setup your Implicit Grant and Hybrid Flows (Grant Type) to:
    1. Allow Hybrid Flow
    2. Allow ID Tokens with Implicit Grant Types

GreenLine Setup and Configuration

  1. Navigate to the Organization Settings by clicking your avatar in the top/right and then clicking Organization Settings from the menu
  2. From the left navigation, choose Single Sign-On (SSO)
  3. Enter your Issurer URL provided by your IdP
  4. Enter your GreenLine application client ID provided by your IdP
  5. The test connection button can be used to verify your Issurer URL.
  6. Choose your login behavior overrides
    1. A login behavior override allows select members of your GreenLine organization to use their GreenLine credentials to gain access to GreenLine and bypass using their SSO credentials
    2. Members who are added to your login behavior override lists will show a ‘Bypass’ badge in your organization member management screen.
  7. Save your changes using the SAVE button at the top right of your configuration screen.

A member of GreenLine can ONLY use SSO credentials when they belong to a single organization. If the GreenLine member belongs to 1+ organizations, they will ONLY be allowed to access GreenLine with their GreenLine email and password.

If a multi-organizational GreenLine member is invited to your SSO organization, they will not have access to your organization unless you add them to your login overrides to bypass using SSO.


Once bypassed, this member can login with their GreenLine credentials and be granted access to your organization. This approach is often used for vendors or 3rd party members who belong to multiple GreenLine organizations OR do not exist in your IDP.

8. Once you have configured your SSO, it needs to be enabled.

Login with SSO

If SSO is enabled for your organization in GreenLine, members can now login using their GreenLine email and SSO credentials.

  1. Navigate to https://greenline.works/login and choose Login with SSO or navigate directly to https://greenline.works/login/sso
  2. Enter your email address
    1. Your IdP email address is the same as your GreenLine email address from your confirmed signup
    2. Your IdP will then prompt you for your password
Did this answer your question?