This guide provides instructions on configuring OpenID Connect (OIDC) Single Sign-On (SSO) for the Tines app integration.
Tines supports the following features:
https://acme.tines.com. To locate your Tenant URL, go to https://login.tines.com, enter your email address, and copy the destination URL that follows the redirect.https://acme.okta.com. https://acme.okta.com/.well-known/openid-configuration, and copy the following values into the matching fields in Tines:
https://acme.okta.com/oauth2/v1/authorizehttps://acme.okta.com/oauth2/v1/tokenhttps://acme.okta.comhttps://acme.okta.com/oauth2/v1/keysYou can optionally enable Just-in-Time (JIT) provisioning by mapping Okta groups to Tines teams and roles. When you enable JIT provisioning, users who sign in for the first time are automatically assigned their mapped team and role, without needing an explicit tenant invitation.
groups as the value for Scopes to fetch the groups claim during user sign-in.groups as the value for SSO-group-based access so that user group information is available to Tines at sign-in.mappings, and optionally tenant_owners_groups and tenant_permission. See Automated user provisioning for details about configuring mappings.To include a group in the ID token's group claim, the Okta group name must start with Tines (case-sensitive), for example Tines-Admins. Okta excludes any group that doesn't have the Tines prefix from the claim.
Go to your Tines tenant URL, for example https://acme.tines.com. You're directed to your Okta org for authentication. Enter your Okta credentials. You're directed back to Tines and signed in.