> This page is for Portal.

> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.emnify.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.emnify.com/_mcp/server.

# Set up an OpenID Connect (OIDC) provider for federated login

> Set up federated login (SSO) for your emnify account with an OpenID Connect (OIDC) provider

The emnify Portal supports federated login using OpenID Connect (OIDC).
Unlike [Microsoft Entra ID](/portal/sso/microsoft-active-directory) and [Google Cloud Platform](/portal/sso/google-cloud-platform), which have built-in integrations, OIDC lets you bring your own identity provider (IdP).
This means you can use any OIDC-compliant IdP - for example, Auth0, Okta, or Keycloak.

> **Note**
>
> This guide uses Auth0 as an example.
> Configuration details may vary across providers, but the required information is the same.

## Prerequisites

* [Auth0](https://auth0.com/) account with permission to create and manage applications
* Access to your Auth0 tenant dashboard
* An [emnify account](/quickstart) using the same email address as your Auth0 login

> **Warning**
>
> Federated login requires that your emnify Portal email matches the email used in Auth0.
> Verify your email in [**User Settings**](https://portal.emnify.com/user-settings).
>
> If you need access with a different email, add another user with the **Administrator** role under **Workspace settings** > [**Users**](https://portal.emnify.com/organisation-settings/users).

## Step 1: Create an application

Log in to the [Auth0 Dashboard](https://auth0.com/).

In the sidebar, go to **Applications** > **Applications**.

Click **+ Create Application**.

Enter a **Name** (for example, `emnify`) and select **Regular Web Application** as the application type.

Click **Create**.

> **Tip**
>
> Copy the **Client ID** and **Client Secret** from **Settings** > **Basic Information**.
> You'll need them later.

## Step 2: Configure application settings

### Add redirect and logout URLs

In your application's **Settings** tab, find the **Application URIs** section.

Under **Allowed Callback URLs**, add the following URL:

```bash
https://prod-e5.okta.com/oauth2/v1/authorize/callback
```

Under **Allowed Logout URLs**, add the same URL:

```bash
https://prod-e5.okta.com/oauth2/v1/authorize/callback
```

### Enable the required grant types

In the **Settings** tab, find the **Authorization Requests** section, then:

Expand **Advanced Settings**.

Open the **Grant Types** tab.

Select the following grant types:

* **Implicit**
* **Authorization Code**
* **Client Credentials**

Finally, click **Save** at the bottom of the page.

> **Info**
>
> Changes may take up to 30 seconds to take effect.

> **Tip**
>
> Keep **Advanced Settings** open.
> You'll copy endpoint values in the next step.

## Step 3: Configure SSO in the emnify Portal

[Log in to the emnify Portal](https://portal.emnify.com/sign/).

Go to **Workspace settings** (building icon) in the top-level navigation and click [**Single Sign-On**](https://portal.emnify.com/organisation-settings/federation) (SSO).

If you need SSO enabled for your account, [contact emnify support](https://support.emnify.com/hc/en-us/requests/new).
Otherwise, click **Add** under the OIDC SSO provider.

Under **General settings**, enter the **Client ID** and **Client Secret** you copied earlier.

Under **Endpoints**, fill in the Portal fields using values from the **Advanced Settings** > **Endpoints** in Auth0:

| Portal field  | Auth0 value                                                    |
| ------------- | -------------------------------------------------------------- |
| Issuer        | Base OAuth URL (for example, `https://your-tenant.auth0.com/`) |
| Authorization | OAuth Authorization URL                                        |
| Token         | OAuth Token URL                                                |
| User Info     | OAuth User Info URL                                            |
| JWKS          | JSON Web Key Set                                               |

Click **Create and Activate**.

Back on **Single Sign-On**, confirm that OIDC appears as a listed **Provider**.

Click **Verify Integration** and complete the login flow.

> **Warning**
>
> You must verify the provider before federated login becomes active.

> **Tip**
>
> For common setup issues, see the [Troubleshooting page](/portal/sso/troubleshooting).