Requirements for Federated Sign-In
This section outlines the access, identity provider capabilities, and configuration details you’ll need before setting up federated sign‑in for Surescripts systems.
Roles Required at Your Organization
The Federation Attributes Edit role, assigned by Surescripts Support, is required to administer federated sign‑in at your organization. You must open a support case to identify the user who will manage federation configuration. This role allows the administrator to configure email domains, federation metadata, and SAML attribute names, and is sufficient to complete setup and validation in Test mode.
Identity Provider Requirements
Your identity provider must meet the following requirements to integrate with Surescripts:
- Supports SAML 2.0
- Publishes a SAML metadata endpoint that is:
- Reachable on the public internet
- Served over TLS
- Signed by a public certificate authority
- Signs SAML assertions (unsigned assertions rejected)
- Accepts signed AuthnRequest messages from Surescripts
- Operates in service‑provider‑initiated mode (IdP‑initiated rejected)
- Uses one identity provider per environment
Surescripts SAML Endpoints
Environment | Surescripts Assertion Consumer Service (ACS) URL |
|---|---|
Staging | https://staging.sso.surescripts.net/Saml2 |
Production | https://sso.surescripts.net/Saml2 |
Required SAML Attributes
Attribute | Purpose |
|---|---|
Required. Identifies the user; must match a domain you've registered in Workbench. | |
firstName | Required. Used to populate the Workbench user profile. |
lastName | Required. Used to populate the Workbench user profile. |
group | Optional. Only required for role mapping. Contains role values that Workbench evaluates and reconciles at each login. For authentication‑only setups, this attribute is not required and can be ignored. |