SingleStore’s Identity Platform
On this page
Note
Currently, this is a public preview feature.
SingleStore Helios’s identity platform is an authentication proxy.
The flow is:
-
The Portal redirects to the authentication endpoint.
-
This creates a request and redirects to a login page.
-
On the login page, after you enter your email address, if SSO is required for your email domain, you will be redirected to your IdP.
If SSO is allowed but not required, you can choose to log in with SSO. . -
When that login process completes, an authentication code is generated and given to the Portal.
-
The Portal exchanges that code for access and refresh tokens.
When the access token expires (within five minutes or less) the Portal asks for a fresh token.
For IdP-initiated login (OIDC only), the login page step is skipped.
Note
Logging in with SSO does not currently grant membership in your SingleStore Helios organization.
When SSO with SingleStore Helios is Already Available
If you already have an SSO connection set up because you followed the old instructions and opened a ticket, that SSO connection will continue to work at least for a while.
To migrate, do a new SSO setup.
IdP-initiated login (OIDC only) will always use the new self-service SSO connection.
Last modified: March 7, 2024