Set Up Single Sign-On

Updated 

Sprinklr supports Single Sign-On (SSO), allowing users to log in using their company credentials instead of separate email and password combinations. This reduces the number of credentials users need to manage while improving security by extending existing authentication controls, such as multi-factor authentication (MFA) and identity lifecycle management, to Sprinklr.

The platform supports integration with standards-compliant SAML and OpenID Connect (OIDC) providers. For Generic OpenID Connect providers, administrators can configure authentication directly through the UI, including advanced options such as PKCE, proxy settings, custom token handling, and profile mapping through Groovy-based adapters.

Enablement

Access to Generic OpenID SSO is controlled by the OPEN_ID_GENERIC_PROVIDER_ENABLED Dynamic Property.

  • When OPEN_ID_GENERIC_PROVIDER_ENABLED is enabled, administrators can configure Generic OpenID Connect (OIDC) providers.

  • When OPEN_ID_GENERIC_PROVIDER_ENABLED is disabled, the Generic OpenID Connect (OIDC) configuration option is not available.

To enable this feature in your environment, reach out to your Success Manager. Alternatively, you can submit a request at tickets@sprinklr.com.

Common SSO Providers

Sprinklr supports any identity provider that is compliant with SAML 2.0 and OpenID.

  • Okta

  • ADFS

  • OneLogin

  • PingFederate 

  • Generic OIDC Providers

Set Up Single Sign-On

To set up Single Sign-On, follow these steps:

1. Click Launchpad or New Tab Space Add New Tab Icon. Under Platform Modules, select All Settings within Settings.

2. From the left pane, select Login & Security Settings and then select Single Sign-Ons.

​

3. In the Single Sign Ons window, click Add Single Sign On in the top right corner.

4. In the Create Single Sign On window, fill in the required details. For more information, see SSO Field Descriptions.

​

​PlatformSettings_SingleSignOn1.png

​

5. Click Save in the bottom right corner.

SSO Field Descriptions

Field

Description

Name

Enter the desired name for the SSO.

Select the Type of Single Sign On

Choose the desired type of SSO. The following options are available: SAML and Open ID.

Depending on the SSO type selected, additional fields will be displayed. See the relevant section for details:

SAML Field Descriptions

Field

Description

Entity Id

Copy and paste the entity ID into Sprinklr.

Note that if you have a metadata file, this corresponds to the entityID= field. If you have a requirements checklist, this corresponds to the Entity Id of Identity Provider field

Issuer Name

Issuer Name is a URL that uniquely identifies your SAML identity provider. SAML assertions sent to Sprinklr must match this value exactly in the attribute of SAML assertions.

Additionally, Issuer Name is an auto-populated field. You can update it based upon your requirements.

Identity Provider Login URL

Copy and paste the Identity Provider Login URL into Sprinklr. Note that if you have a metadata file, this will be in the <md:SingleSignOnService, Location= field.

You may see different locations for a post, redirect, other types of bindings. They always seem to be the same, so it should not matter which you paste in but 90%+ of clients use POST bindings so when in doubt use that. If you have a requirements checklist, this will be in the AuthNRequest: POST or REDIRECT bindings? field. 

Identity Provider Logout URL

Copy and paste the Identity Provider Logout URL into Sprinklr.

SAML User ID Type

Choose the desired SAML User ID Type. The following options are available:

  • If the customer is authenticating on email, leave at the default Assertion contains User's sprinklr.com username selection. 

  • If they are authenticating on an ID value and not email, select Assertion contains the Federation ID from the User object instead.

SAML User ID Location

Choose the desired SAML User ID Location. The following options are available:

  • If the customer is sending the authentication value (email or ID) in the NameID, leave at the default User ID is in the Name Identifier element of the Subject statement selection.

  • If the customer is sending the authentication value in another attribute, then select User ID is in an Attribute element and enter the name of the attribute that the authentication value will be sent in.

You can determine whether the customer is sending the authentication value in the NameID or another attribute by asking them directly.

Request Binding

Select the desired request binding. The following options are available:
HTTP POST
HTTP Redirect

User Not Provisioned Error Message

Enter an error message (using the Rich Text Editor) that you wish to be displayed when any user is not provisioned to login. 

Do you want to enable SSO for advocacy?

Check the box and select the Name from the drop-down menu & enter the desired Attribute. 

To learn how to enable SSO in Advocacy, refer to Single Sign-On (Advocacy).

Use new SSO Certificate

Check box for Use New SSO Certificate. This box needs to be checked for every SSO enablement.

Request Signature Method

Select the Request Signature Method from the drop-down menu.
You can check the metadata file to confirm the Request Signature Method.
In the metadata file, it should look something like this <ds:DigestMethod Algorithm=“ http://www.w3.org/2001/04/xmlenc#sha256“/ >.

Identity Provider Certificate

Fill out the Identity Provider Certificate. In the metadata file, this corresponds to the <ds:X509Certificate> field.

Open ID Field Descriptions

Field

Description

Provider

Select the Open ID provider from the drop-down list.

  • Social Channels: If you select any social channel (For example: Google, Facebook, Twitter, Instagram) as the Provider, then you are not required to fill out any additional steps  

  • Generic: If you select Generic as the provider, provide the necessary configuration details. For more information, see Generic OpenID SSO Field Descriptions.

Note: Access to Generic OpenID SSO is controlled through a Dynamic Property (DP). To enable this feature in your environment, reach out to your Success Manager. Alternatively, you can submit a request at tickets@sprinklr.com.

Generic OpenID SSO Field Descriptions

Field
Required/Optional
Description

Client Key

Required

OAuth 2.0 client ID.

Client Secret

Required

OAuth 2.0 client secret.

Authorize Endpoint URL

Required

The OAuth authorization endpoint URL.

Token Endpoint URL

Required

The OAuth token exchange endpoint.

User Info URL

Optional

Optional endpoint to fetch user profile info.

Scope

Optional

Scopes like openid, profile, etc.

PKCE Enabled

Optional

Toggle PKCE flow support.

Request Via Proxy

Optional

If enabled, requests are routed via Sprinklr proxy.

Proxy Host

Optional

Proxy hostname (required if proxy enabled).

Proxy Port

Optional

Proxy port (required if proxy enabled).

Access Token Field

Optional

Token field name in response (default: access_token).

Token Headers Adapter

Optional

Add Groovy script to modify token request headers. For more details, see Advanced Configuration .

Token Params Adapter

Optional

Add Groovy script to modify token request parameters. For more details, see Advanced Configuration.

Profile Adapter

Required

Add Groovy script to parse user profile from user info response. For more details, see Advanced Configuration.

Generic OpenID Advanced Configuration (Optional)

Sprinklr supports advanced scripting for token handling and profile creation:

1. Token Request Adapters

Customize token request headers and parameters using Groovy scripts.

  • tokenHeadersAdapter: Modify headers (e.g., Authorization, Content-Type).

  • tokenParamsAdapter: Add custom parameters like aud, scope, etc.

2. Profile Adapter

Process the user info API response using Groovy and map it to a Sprinklr user profile.

Note: You can also make calls to userInfoEndpoint within the Groovy script using passed-in input parameters.

Sample Code

​String jwt = TOKEN_DETAILS.get("token") ​String sub = JWT.parseSubject(jwt) ​def res = MAP_UTILS.newMap(); ​res.put("SN_ID", sub); ​res.put("TYPE", "KEYCLOAK"); ​return res ​

​

Map Profile Custom Fields

​

The Profile Adapter also supports mapping user attributes returned by the identity provider to custom profile fields. This allows additional user information received during authentication to be stored in the user's profile and used across Live Chat workflows.

For example, if the identity provider returns attributes such as Customer Segment, Loyalty Tier, Country, Region, or Policy ID, you can map these values to custom profile fields. Once stored in the user's profile, they can be used to personalize customer experiences and support workflow-specific use cases.

String jwt = TOKEN_DETAILS.get("token")String sub = JWT.parseSubject(jwt)def res = MAP_UTILS.newMap();res.put("SN_ID", sub);res.put("TYPE", "KEYCLOAK");def additional = MAP_UTILS.newMap()additional.put("loginAttempt", ["199"])additional.put("_c_68a482eb32f5986aa3a8181a", ["test value 1234"])additional.put("_c_6a01b4a819ff2615b7644b1f", ["LCQA3"])additional.put("_c_65fd2042ebb4bf761908e951", ["Yes"])additional.put("_c_677e4fda194a8b226391cdb8", ["Append"])res.put("ADDITIONAL", additional)return res;

​