---
title: "General OAuth 2.0 SSO Setup"
canonical: "https://help.agiloft.com/space/HELP/65275485/General%20OAuth%202.0%20SSO%20Setup"
format: markdown
---
If you don’t use Microsoft Entra or Google for identity and access management, you can use this article for general guidance on setting up single sign-on (SSO) with any OAuth 2.0 identity provider (IdP). This article also includes instructions on how to log in with SSO after the integration and make sure other users log in with SSO as well.

For specific setup instructions with Microsoft Entra or Google, see [Microsoft OAuth 2.0 and OIDC SSO Setup](https://agiloft-public.atlassian.net/wiki/spaces/HELP/pages/43718530) or [Google OAuth 2.0 and OIDC SSO Setup](https://agiloft-public.atlassian.net/wiki/spaces/HELP/pages/43716014).

> ℹ️ **Prerequisites**
> ℹ️ 
> ℹ️ - Users can't log in with OAuth 2.0 SSO unless they already have a user record in Agiloft CLM. Before setting up SSO, make sure each user who will use SSO has a user record in your KB. You can set up SCIM provisioning to create and update user records automatically. See [Provision Users with SCIM](https://agiloft-public.atlassian.net/wiki/spaces/HELP/pages/779649034) for details.
> ℹ️ - Also make sure the data in the user records meet the requirements for identifying users in your IdP. Some providers match on email address and others match on login.

# Set Up Your IdP

Before you can complete the Agiloft CLM setup, you need to create an OAuth client for Agiloft CLM in your IdP. Refer to your provider’s documentation for instructions on adding the OAuth client. 

When you configure the client, you’ll need to know the redirect URI to use for your KB. You’ll also need to make note of certain client configuration details so you can enter them in Agiloft CLM. This section lists the information you need.

### Define the Redirect URI

When you supply the redirect URI for your KB, enter the URI as follows: `https://HOSTNAME/ui/oauth20sso`

Where HOSTNAME is the hostname for your Agiloft CLM instance. For example: `example.agiloft.com`

The complete redirect URI looks like this example: `https://example.agiloft.com/ui/oauth20sso`

### Note the OAuth Client Details

As you complete the client configuration, we recommend saving the following values to a note so you can copy them into Agiloft CLM later:

- The redirect URI you created
- The Client ID and Client Secret for the OAuth client
- The OAuth 2.0 authorization endpoint for your IdP
- The OAuth 2.0 token endpoint for your IdP

When the IdP setup is completed, proceed to the next section to set up SSO in your KB.

# > Macro (anchor)

Set Up SSO in Agiloft CLM

Follow the steps below to set up SSO in Agiloft CLM.

1. Go to **Setup > Access > Configure OAuth 2.0 Profiles** and click New to add a profile.
2. Leave the "Use full OAuth account name as a KB login name / email" checkbox selected.
3. Enter a name for the OAuth 2.0 provider.
4. For the role of this OAuth 2.0 Provider, select OAuth20_SSO.
5. Complete the remaining fields:
  1. **Redirect URI**: The URI you created when setting up the OAuth client.
  2. **Client ID / Application ID / Consumer Key**: The Client ID for the OAuth client.
  3. **Client / Consumer Secret**: The Client Secret for the OAuth client.
  4. **Authentication URI**: The OAuth 2.0 authorization endpoint from your IdP.
  5. **Token URI**: The OAuth 2.0 token endpoint from your IdP.
6. Click Finish to save the profile.
7. Finally, make sure each user who will log in with SSO has a user record in Agiloft CLM. In addition, make sure the data in the record meets the requirements for identifying users in your IdP. Some providers match on email address and others match on login. For information about creating user records, see [User Management](https://agiloft-public.atlassian.net/wiki/spaces/HELP/pages/926744591).

Now that Agiloft is configured to allow SSO, proceed to [Log in with SSO](#sso_login) for details on how to log in.

# > Macro (anchor)

Log in with SSO

> Macro (include)

# > Macro (anchor)

Force SSO Login

> Macro (include)