Integrations
Identity Providers
An Identity Provider signs developers in to your API Portal. Connect Microsoft Entra ID, Amazon Cognito, or any OpenID Connect provider. Saving one sends Apiable a setup request, and Apiable completes the connection.
An Identity Provider signs developers in to your API Portal. You enter the provider's details in the dashboard under Integrations → Identity Providers, and saving them sends Apiable a request to connect it. Apiable completes the connection on its side. You then turn the provider on and assign it to the companies whose developers should sign in through it. An Identity Provider controls who can sign in to your portal, not what an API call is allowed to do.
What is an Identity Provider in Apiable?
An Identity Provider is the external system that authenticates the people who sign in to your API Portal. The portal sends a developer to the provider, the provider verifies them, and the developer returns to your portal signed in.
Identity Providers are a plan feature. When your plan does not include them, the section does not appear in the sidebar.
How is an Identity Provider different from an Authorization Server?
An Identity Provider signs people in to your API Portal. An Authorization Server issues the OAuth2 tokens your gateway validates for machine-to-machine API calls. They solve different problems and are configured separately.
| Identity Provider | Authorization Server | |
|---|---|---|
| Job | Signs developers in to your API Portal | Issues OAuth2 access tokens for API calls |
| Who it serves | People signing in to the portal | Subscriptions and their machine clients |
| Where you set it up | Integrations → Identity Providers | Integrations → Authorization Servers |
| Examples | Microsoft Entra ID, Amazon Cognito, OIDC | Keycloak, Auth0, Duende |
Which identity providers does Apiable support?
Apiable supports three Identity Providers: Microsoft Entra ID, Amazon Cognito, and a generic OpenID Connect (OIDC) option. The OIDC option works with any standards-compliant OpenID Connect provider.
| Provider | Use it for |
|---|---|
| Microsoft Entra ID | Signing in developers from a Microsoft Entra ID tenant or verified domain. |
| Amazon Cognito | Signing in developers from an Amazon Cognito user pool. |
| OpenID Connect (OIDC) | Any standards-compliant OpenID Connect provider, configured by issuer URL. |
The setup wizard on Getting Started (Run the wizard) has its own sign-in step, offering Microsoft Entra ID, Okta, and Generic OIDC. What you enter there is saved with the wizard's progress. It does not create a provider on the Identity Providers page.
How does connecting an Identity Provider work?
It happens in two parts. You create the connection in the dashboard, and saving it sends Apiable a setup request. Apiable then completes the connection on its side. Until it does, the provider's sign-in fails, so keep the provider inactive until Apiable confirms.
- Open Integrations → Identity Providers and select + Add AuthN. The next screen lists the three provider types, with Microsoft Entra ID selected.
- Choose the type and continue. The connection form opens on the Authorization tab.
- Fill in the credentials. The fields differ per type, and each task page lists them. The Instructions panel beside the form shows the setup notes for the type, including the redirect address to register with your provider.
- Switch off the Active toggle above the tabs. A new provider starts active.
- Save. Apiable receives a request to connect the provider.
- On Details, set how the login button looks. On Assignment, choose the companies it covers, and leave Force SSO off for now.
- When Apiable confirms the connection, turn the provider on and test a sign-in through it. Use an email address that has no password account on your API Portal.
What do the three tabs do?
A provider has three tabs: Authorization for credentials, Details for how it appears, and Assignment for the companies it covers. The Assignment tab stays disabled until you save the provider for the first time.
| Tab | What you set |
|---|---|
| Authorization | The provider's connection details. The fields depend on the provider type. |
| Details | Display Name, which is required, plus the display icon and the display mode, Standalone or Grouped. |
| Assignment | Assign all companies, Force SSO, and the companies the provider covers. |
The Active toggle above the tabs decides whether the provider appears on your API Portal login page. A change to it, or to company assignments, can take up to five minutes to reach the login page. Turning a provider off does not undo its company assignments. See What does Force SSO do? for what that means.
What do Standalone and Grouped display modes do?
Display mode decides how an active provider appears on your API Portal login page. Standalone gives the provider a button of its own. Grouped puts it behind a shared Sign in with SSO button.
A Standalone provider shows a button reading "Continue with" and its display name, with its icon. Every visitor sees it, whichever company they belong to. Grouped providers share one Sign in with SSO button. It asks for an email address and sends the developer to the provider their company is assigned to, so a Grouped provider is reached only through the companies assigned to it.
How does company assignment work?
A company is a set of email domains, and each company has one Identity Provider at a time. When a developer enters their email at sign-in, the portal finds their company and sends them to that company's provider.
Companies are listed under Consumers → Company, which appears when company registration is turned on in Portal details. A company is created when a developer registers on your API Portal with company registration on.
- Assign a company on the provider's Assignment tab, or in the Identity Provider field on the company's Details tab. Assigning a company to one provider moves it off any provider it had.
- With Force SSO off, a developer routed from the email step can still sign in with a password on the provider's page.
- Assign all companies does not add the provider to email routing. Routing follows each company's own assignment, so assign companies to the provider individually when developers should be routed to it. Developers reach a provider set to Assign all companies through its Standalone button.
Saving the Assignment tab with Assign all companies on clears the companies you selected individually. When someone signs in through such a provider for the first time and no company exists for their email domain, Apiable creates one and assigns it to the provider.
What does Force SSO do?
Force SSO makes the provider the only way in for developers whose company is assigned to it. It is one switch per provider and applies to every company the provider covers. Read what it changes before you turn it on, because it can lock out developers who already sign in with a password.
With Force SSO on:
- Developers from assigned companies get no password option. After the email step, the portal sends them to the provider.
- New developers from those companies are sent to the provider when they try to create an account.
- Existing password accounts on those domains are locked out. An account keeps the sign-in method it was created with, so the provider refuses it and the developer sees "Different login method required".
- With Assign all companies also on, password sign-up is refused for your whole API Portal, whatever the email domain, while the provider is active. Developers see "SSO required for this email".
- Turning the provider off does not release its companies. Their developers still get no password option, and the provider's sign-in is gone. To release a company, remove it from the provider, or turn Force SSO off.
Before you turn Force SSO on:
- Confirm that Apiable has completed the connection and that a test sign-in through the provider works.
- Check which developers from the assigned companies already sign in with a password in API Consumers. They lose access once Force SSO is on.
- On the Assignment tab, turn Force SSO on and save.
What does a developer see at API Portal login?
The login page shows a button for each active Standalone provider, a Sign in with SSO button when any active provider is Grouped, and an email field with Continue. Choosing a provider sends the developer to it, and back to your portal once they authenticate.
After Continue, the portal looks up the developer's company. If the company is assigned to a provider, the developer goes to that provider's sign-in page, where a password field is also offered unless Force SSO is on. Otherwise the developer signs in with a password.
Each developer account keeps the sign-in method it was created with: a password, or one Identity Provider. Signing in another way is refused with "Different login method required".
What limits and permissions apply?
Your plan decides which provider types you can connect. Choosing a type your plan does not include opens an upgrade prompt, and the Identity Providers page shows how many providers your plan includes.
- A provider cannot be deleted while companies are assigned to it. Remove the assignments first.
- In the dashboard, the Owner, Organisation Admins, Portal Admins, and Configuration Owners get the controls to add, change, and delete providers. See Members and roles.
Troubleshooting
Match what you see to the fix.
| What you see | What to do |
|---|---|
| "This identity provider is not configured correctly. Please contact your administrator." on the API Portal | Apiable has not completed the connection. Turn the provider off, and turn it on when Apiable confirms the connection. |
| "Different login method required" | The developer's account was created with a password, or through another provider. It can only sign in the way it was created. If Force SSO blocks their password, turn Force SSO off for that provider. |
| "SSO required for this email" when a developer signs up | Their email domain is covered by a Force SSO provider, or an active provider has both Force SSO and Assign all companies on. They sign up through the provider, or you turn Force SSO off. |
| A developer reaches a sign-in page with no password field and no working provider | Their company is assigned to a provider that has Force SSO on but is turned off. Turn it on, remove the company from it, or turn Force SSO off. |
| A change to Active or to assignments does not show on the login page | Allow up to five minutes, then reload the login page. |
| Delete cannot be confirmed | Companies are still assigned to the provider. Remove them on the Assignment tab first. |
| + Add AuthN is greyed out | Your plan does not include Identity Providers, or your role lacks the integration controls. |
| "Your account does not currently possess a sufficient role or permissions required to manage gateway integrations." | Ask an Organisation Admin for a role with integration controls, such as Configuration Owner. |
Where do Identity Providers fit in your portal?
Identity Providers decide who can sign in to the API Portal you give your API consumers. Authorization Servers and scopes then govern what those consumers' API calls can do once they subscribe.
Where to next
Connect Microsoft Entra ID
Connection Name, Tenant ID or Domain, Client ID, and Secret.
Connect Amazon Cognito
Connection Name, User Pool ID, Region, and App Client ID.
Connect an OpenID Connect provider
Connection Name, Issuer URL, Client ID, and an optional discovery URL.
Authorization Servers
The OAuth2 side: how tokens for API calls are issued and validated.