> For the complete documentation index, see [llms.txt](https://skedway.gitbook.io/skedway-documentation/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://skedway.gitbook.io/skedway-documentation/sso-single-sign-on-saml-2.0/general-specifications.md).

# General Specifications

This document aims to define a base process and guide the configuration of the SSO SAML (Security Assertion Markup Language 2.0) with the Identity Provider (IdP) of contractor and the Service Provider

## About

SSO lets users sign in just one time to get access to all their enterprise cloud applications. When SSO is set up, users can sign in to their third-party IdP, then access Skedway apps directly without a second sign-in

## Procediments

### Sending information to the Service Provider (SP).

The first step is to provide some basic information to Skedway team start up the SSO Configuration Process.

The person in charge of integration must send / make available the following artifacts:

* **Metadata.xml** file and / or the subscriber's **SAML metadata URL** so that it can be configured at Skedway Service Provider. If possible, send us detailed documentation.
* **Desired subdomain:** Prefix to be used in order to access Skedway environment with SSO, Eg .: my-agenda.skedway.com.

### Identity Provider (IdP) configuration.

Inform the Skedway team what data/information will be required for the sequence of operation and configuration. By default the Skedway team will make available the following artifacts after the first submission of information:

1. Skedway **metadata.xml** file and/or the **URL of the SAML** metadata for being configured in the subscriber's Identity Provider.
2. **EntityID** that should be linked in the integration

**Unique key field:** `emailAdress`

{% hint style="warning" %}
Skedway performs an entire identification process based on the **user's email**. Therefore, this is the key identification field and must be available in order to match with the same information registered at Skedway Platform.
{% endhint %}

## Tests and final validation

### Skedway

After having all information available and the Identity Provider (IdP) already configured, the final validation and tests must be performed by Skedway Integration team.

### Subscriber

After final approval (by Skedway Integration Team), the subscriber will be able to carry out the final validation of the SSO at Skedway Web Console and App environment.

{% hint style="info" %}

* When needed, we ask the customer to provide a test user, (account), who is registered in their directory to pass through SSO.
* This account will also be used to identify and find possible problems that users are reporting, like: access problems, login, scheduling, etc.
* The release of this test account must be agreed with the customer.
  {% endhint %}

## Aditionals

**User update:** Skedway SSO also covers the user sync scheduled service interval. The service runs once a day, validating and updating the users of the integrated directory, during this interval, if a user is added or updated, when that user logs in via SSO, their credentials will be validated and will be registered and/or updated in the Skedway directory.

{% hint style="info" %}
When needed, we ask the customer to provide a test user, (account), who is registered in their directory to pass through SSO. This account will also be used to identify and find possible problems that users are reporting, like: access problems, login, scheduling, etc.
{% endhint %}

{% hint style="info" %}
The release of this test account must be agreed with the customer.
{% endhint %}

### Support

If you have any question regarding this topic, please contact our support team.

**E-mail:** <suporte@skedway.com>\
**Skedway service desk portal**

{% embed url="<https://help.skedway.com/hc/pt-br>" %}
