Skip to main content
About the Resource Center

Add multiple single sign-on providers to Genesys Cloud

Genesys Cloud allows you to configure up to 30 single sign-on (SSO) integrations with the same identity provider or a mix of identity providers. To help you create your SSO integrations, Genesys Cloud enables you to import a SAML metadata file that you receive from your identity provider. Importing a SAML metadata file, which contains the relevant configuration details and certificate information, automatically populates the necessary fields in the integration.

Single Sign-On page

To track multiple SSO integrations, Genesys Cloud displays the integrations as a list on the Single Sign-On page. The page provides a summary of each integration including the log in name, logo, identity provider, and certificate expiration details. In the Action column, click More to display a menu that allows you to edit and delete an integration. On the Name, Identity Provider, and Certificate Expiration column headers, click Sort to rearrange the view in ascending or descending order.

The page also provides options that allow you to add an identity provider and download a Genesys certificate. To send a Genesys certificate to an identity provider, click Download Genesys Certificate.

Click the image to enlarge.

Customize the login screen for each SSO integration

You can customize how to display each SSO integration with a different login name and a logo of your choice. You can choose to display the name or the logo, or both the name and logo. The choice you make determines how the SSO integration displays on the Single Sign-On and Genesys Cloud login page.

To conserve space, only six SSO integrations appear directly on the Genesys Cloud login page.

If you have more than six SSO integrations, they appear in a list on the login page.

Create an SSO integration

Genesys Cloud metadata 

To pair an SSO integration between Genesys Cloud and an identity provider, configure settings on both ends. Identity providers supply you with a metadata file that contains the issuer URI, single sign-on URI, and single log out URI to enter into Genesys Cloud as you configure your organization’s identity provider account. You can generate a SAML metadata file with the Genesys Cloud metadata and certificate information that an identity provider must use to configure settings on their end. 

To create an SSO integration:

  1. Click Admin.
  2. Under Integrations, click Single Sign-on.
  3. Click Menu IT and Integrations > Single Sign-on.
  4. Click Add an Identity Provider.
  5. Enter the name that you want to assign to your integration.
  6. To display the logo on the Genesys Cloud login page, select Display Name On Login Page.
    Note: If you have more than six identity providers, the Display Name On Login Page option is not available.
  7. Click Identity Provider Name and you can select one of the available, fully supported, identity providers or enter a new identity provider name.
    Note: The Identity Provider Name list contains a set of the most common providers. If you do not see your identity provider listed, you can add them by typing their name. After you save the configuration, the new identity provider appears in the list.
  8. Click Select logo and upload the logo image file that you want to display on the login page. Alternatively, you can drag and drop the logo image file.
    Note: The logo image file must be in SVG format and cannot be larger than 25 KB in size.
  9. To import the metadata file that your identity provider sent to you, in the Identity Provider Data section, click Select SAML metadata to import. Alternatively, you can drag and drop the metadata file.

After you import the metadata file, notice that the required fields are automatically populated and the encoded public x509 certificate for SAML signature validation is available.

  1. Click Save.

Genesys Cloud service provider data

When you click Save, Genesys Cloud generates the SAML metadata that your identity provider uses when configuring your identity provider account. 

Note: The generated metadate file includes the Issuer URI, the Assertion Consumer Service, and the Single Logout URI.
  • To download a SAML metadata file that contains the Genesys Cloud metadata and certificate information that an identity provider must use to configure settings on their end, under Genesys Cloud Metadata, click Download Metadata.
  • If you only need a Genesys certificate to send to an identity provider, under Single Logout URI, click Download Certificate.

 

SAML attributes

If the following extra SAML attributes are present in the assertion, Genesys Cloud acts on the attributes. The attributes are case-sensitive. 

Attribute nameAttribute value
OrganizationName 
  • For identity provider-initiated single sign-on: Use the organization short name.
  • For service provider-initiated single sign-on: Make sure that the organization name matches the organization name that you select. It is applicable when an organization maintains multiple Genesys Cloud organizations using a single identity provider. 
ServiceName 

(Optional) A valid URL for the browser to be redirected to after successful authentication, or one of the following keywords:

  • directory (redirects to the Genesys Cloud Collaborate client)
  • directory-admin (redirects to the Genesys Cloud Admin UI)