OIDC Setup (General)

Prerequisites

🚧

Making edits?

Before you edit your SSO configuration, make sure you are logged into MyMoveworks. Otherwise, you will not be able to log in and update your SSO configuration details.

SSO Prerequisites

  • Have sufficient privileges to create & configure an OIDC application.

Moveworks SSO Prerequisites

  • Your Moveworks Environment should be initialized in order to continue. (Verify with your Account Team if this has been completed)

  • Note the following values.

    • data_center_domain - the data center where your organization is hosted (see table below).

      Data Centerdata_center_domain
      United States (default)moveworks.com
      Canadaam-ca-central.moveworks.com
      EUam-eu-central.moveworks.com
      Australia / Asia Pacificam-ap-southeast.moveworks.com
      Government Secure Cloudmoveworksgov.com
    • subdomain - your organization's login subdomain. This should match your customer_id, which can beverified from the General Information Page.

      🚧

      Warning

      Make sure to use the unique subdomain. For example, if you're organization's login subdomain is acme.moveworks.com, then your subdomain is acme and your data_center_domain is moveworks.com which is part of the US Data center.

    • customer_id - The unique identifier for your organization . This is stored as Org Name under Organization Details > General Information

      ❗️

      The Org name cannot be changed. Once set, the same value should be used in all cases.

      In exceptional cases where you would like Moveworks to support your organisation with a different subdomain value. Please reach out to Moveworks Support.

Configuration Steps

Create OIDC Application

Go to your SSO Admin Portal & create a new OpenID Connect (OIDC) application. Please configure your redirect and login urls based on your Moveworks SSO properties.

  1. App Name: Moveworks.

  2. Sign-in Method: OpenID Connect as the sign in method.

  3. Login URL (aka Home Page URL): https://{{subdomain}}.{{data_center_domain}}

  4. Redirect URL: https://{{subdomain}}.{{data_center_domain}}/login/sso/oidc

  5. Application Icon:


Add OIDC Configuration in MyMoveworks

  1. Note your OIDC Configuration variables from your SSO platform

    • Issuer URL: (called idp_issuer)
    • Client ID: (called idp_client_id)
    • Client Secret (called idp_client_secret)
  2. Navigate to SSO Settings in MyMoveworks

  3. If you already see a studio config, edit it. Otherwise, choose Create.

  4. Add your configuration using the values you've noted above

  5. Click Submit.

  6. Wait a few minutes, then attempt to log into your instance at https://{{subdomain}}.{{data_center_domain}}