# Federated Identity Providers

MyNamirial supports **Single Sign-On (SSO)** through federation with an external Identity Provider (IdP). When active, users belonging to your organisation authenticate through your own IdP instead of entering a MyNamirial password.

## Supported protocol

MyNamirial supports federation via **OIDC (OpenID Connect)**. SAML 2.0 support is planned and not yet available.

## What you need to provide

To configure federation, send the following information to Namirial.

### 1. Email domains

The list of email domains whose users will authenticate via your IdP — for example `company.com`, `company.it`.

MyNamirial uses this list to automatically route users to the correct IdP at sign-in time. Include every domain in use; users on unlisted domains will be directed to the standard MyNamirial login instead.

### 2. OIDC discovery endpoint (well-known)

The URL of your IdP's discovery document, for example:


```
https://idp.company.com/.well-known/openid-configuration
```

MyNamirial reads this URL automatically to retrieve the authorization endpoint, token endpoint, JWKS keys, and supported algorithms.

### 3. Client ID and Client Secret

Register a new OAuth2/OIDC client on your IdP with MyNamirial as the Relying Party, then share:

- **Client ID**
- **Client Secret**


> Before creating the client, ask Namirial for the **Redirect URI** to add to the allowed list on your IdP.


### 4. Technical contact

Name and email (or phone) of a technical contact on your side, available during the setup and testing phase and for any future changes to the IdP configuration.

## Summary

| What | Who provides it |
|  --- | --- |
| Email domains | You |
| OIDC well-known endpoint | You |
| Client ID | You |
| Client Secret | You |
| Redirect URI | Namirial → You |
| Technical contact | You |