Skip to main content
Available in v3.4.0 and later.
Rallly supports three SSO options: Google, Microsoft (Entra ID), and any provider that speaks OpenID Connect (OIDC). You can enable more than one at a time.
Accounts using the same email address are linked together. This assumes your identity provider only issues verified email addresses.

Google

  1. Open the Google Cloud Credentials tab: https://console.developers.google.com/apis/credentials
  2. Create an OAuth client ID. This gives you a GOOGLE_CLIENT_ID and GOOGLE_CLIENT_SECRET.
  3. Set Authorized redirect URIs to include your full domain and the callback path:
The client ID of your Google application.
The client secret of your Google application.

Microsoft

Follow the Microsoft Entra ID quickstart to register an application.After creating the application, set the redirect URI to:
On a multi-tenant endpoint (MICROSOFT_TENANT_ID set to common, organizations or consumers) any tenant can assert any email address, so Rallly needs Microsoft to confirm the address before it creates an account from it. Microsoft does not include that information unless the app registration asks for it, so a multi-tenant registration must emit the verified email claims: without them every new Microsoft sign-in fails with “Your email address is not verified”. Work and school accounts are vouched for by verified_primary_email and verified_secondary_email; personal Microsoft accounts (Outlook, Hotmail, Live) are vouched for by xms_edov, which Microsoft only emits alongside the email claim. Add all four as optional claims on the ID token. In the app registration open Token configuration, choose Add optional claim, pick the ID token type and tick email, verified_primary_email, verified_secondary_email and xms_edov. If the registration lives in an Azure AD B2C tenant, that blade is hidden; open Manifest instead and add these entries to the optionalClaims.idToken array, keeping any claims already there:
If optionalClaims is null, replace it with { "idToken": [ ...the four entries... ] }.Once the claims are present, a Microsoft sign-in whose address Microsoft does not vouch for fails with “Your email address is not verified”. Existing users are not affected. Single-tenant registrations do not need this.
With CONFERENCING_ENABLED=true, the Microsoft registration also powers the Microsoft Teams integration; there are no separate Teams variables. Add the redirect URI:
Under API permissions, add the delegated Microsoft Graph permissions OnlineMeetings.ReadWrite, User.Read and offline_access. If your organization does not let users consent to apps, choose Grant admin consent on the same page. Teams meetings can only be created for work or school accounts, so with MICROSOFT_TENANT_ID set to common or consumers Teams connects through the organizations endpoint; with a tenant ID it connects through that tenant.
The tenant ID of your Microsoft application.
The client ID of your Microsoft application.
The client secret of your Microsoft application.

OpenID Connect (OIDC)

If your identity provider supports OAuth 2.0 with OpenID Connect, you can use it to authenticate users on your Rallly instance.

Required scopes

Your OAuth 2.0 application needs these scopes:
  • openid — perform authentication (required).
  • profile — access name and picture.
  • email — access the user’s email address.

Callback URL

Your identity provider should redirect the user back to:

Configuration

All required fields must be set for OIDC to be enabled.
default:"OpenID Connect"
Display name of your provider as shown on the login page.
required
URL of the .well-known/openid-configuration endpoint for your OIDC provider.
required
The client ID of your OIDC application.
required
The client secret of your OIDC application.
default:"name"
Path to the claim that contains the user’s name.
default:"email"
Path to the claim that contains the user’s email address.
default:"picture"
Path to the claim that contains the user’s profile picture.
Use dot notation in _CLAIM_PATH fields to access nested objects.