Integrations
Connect Microsoft Entra ID
Connect Microsoft Entra ID as an Identity Provider for your API Portal. Enter a Connection Name, Tenant ID or Domain, Client ID, and Secret. Saving sends Apiable a setup request, and Apiable completes the connection.
You connect Microsoft Entra ID as an Identity Provider under Integrations → Identity Providers. You name the connection, enter your tenant or domain and the app registration's client ID and secret, then save. Saving sends Apiable a setup request, and Apiable completes the connection on its side. Once Apiable confirms, you turn the provider on and assign it to the companies whose developers should sign in through it.
Where do you connect Microsoft Entra ID?
Open Integrations → Identity Providers, select + Add AuthN, and continue with Microsoft Entra ID, which is selected by default. The connection form opens on the Authorization tab.
- Open Integrations → Identity Providers.
- Select + Add AuthN. The next screen lists the provider types, with Microsoft Entra ID selected.
- Continue to the connection form, which opens on the Authorization tab.
You can also start from Integrations → Integrations: in the Identity Providers category, choose Set up on the Microsoft Entra ID card.
What does each Microsoft Entra ID field mean?
The Authorization tab asks for a connection name and the app registration's details. Required fields are marked.
| Field | What to enter |
|---|---|
| Connection Name | A name for this connection inside Apiable. Required. |
| Tenant ID or Domain | Your Microsoft Entra ID tenant ID, or a verified domain of the tenant. A tag beside the field shows Tenant or Domain. |
| Client ID | The application (client) ID of the app registration. Required. |
| Secret | A client secret of that app registration. Entered in a masked field. |
The Instructions panel beside the form shows the setup notes for Microsoft Entra ID, including the redirect address to register on your app registration.
How do you save the connection and get it working?
Turn the provider off, save it, and wait for Apiable to complete the connection. Saving sends Apiable a setup request. Until Apiable completes it, an active provider's sign-in fails.
- Switch off the Active toggle above the tabs. A new provider starts active.
- Save. Apiable receives a request to connect the provider, and the Assignment tab becomes available.
- When Apiable confirms the connection, switch the Active toggle on and save.
- Test a sign-in through the provider on your API Portal. Use an email address that has no password account on the portal, because an account created with a password cannot sign in through a provider.
How do you set the display name, icon, and display mode?
Open the Details tab. Enter a Display Name, which is required, add a display icon, and choose the display mode, Standalone or Grouped. These control how the provider appears on your API Portal login page.
A Standalone provider gets its own "Continue with" button with its display name and icon, shown to every visitor. A Grouped provider sits behind the shared Sign in with SSO button and is reached only by developers whose company is assigned to it. See Identity Providers for how each mode looks.
How do you assign companies and force SSO?
Open the Assignment tab, which unlocks after the first save. Select the companies whose developers should be routed to Microsoft Entra ID, then save. Leave Force SSO off until sign-in works and you have checked for existing password accounts.
- On Assignment, search the Companies list and select each company, or use Select All.
- Leave Force SSO off for now.
- Save the assignment.
Assign all companies does not route developers to the provider by email domain, and saving with it on clears the companies you selected individually. See How does company assignment work?.
Troubleshooting
Match what you see to the fix. Sign-in problems show on your API Portal login page.
| What you see | What to do |
|---|---|
| The Assignment tab is greyed out | The provider has not been saved yet. Complete the Authorization tab and save, then open Assignment. |
| "This identity provider is not configured correctly. Please contact your administrator." | Apiable has not completed the connection. Turn the provider off, and turn it on when Apiable confirms. |
| The provider does not appear on the login page | Check that the Active toggle is on and the display mode is Standalone. A Grouped provider shows only through Sign in with SSO. Allow up to five minutes after a change. |
| The field shows a Domain tag when you meant a tenant ID | The value contains a dot or starts with http. Enter the plain tenant ID to have it recorded as a Tenant. |
| "Different login method required" | The developer's account was created with a password or through another provider, and can only sign in that way. If Force SSO blocks their password, turn Force SSO off for this provider. |
| A developer still sees a password field when you expected SSO only | Force SSO is off for this provider, or the developer's company is not assigned to it. Force SSO is one switch on the Assignment tab and applies only to the companies assigned to the provider. |
Where to next
Identity Providers
How connections, assignment, and Force SSO work together.
Connect Amazon Cognito
Sign in developers from an Amazon Cognito user pool.
Connect an OpenID Connect provider
Connect any standards-compliant OpenID Connect provider.
Authorization Servers
The OAuth2 side: tokens for API calls, not portal sign-in.