Set up single sign-on
This guide explains how to set up single sign-on (SSO) between the applications of one organization, so that a user who has signed in to Casdoor opens the other applications without signing in again.
Learning outcomes
- Turn on automatic sign-in for an application.
- Implement silent sign-in on the home page of your application.
- Offer sign-in in a popup window or an iframe.
- Let users move between applications from the Casdoor home page.
What you need
- Two or more applications in the same organization
- An application frontend that you can change, with casdoor-js-sdk or casdoor-react-sdk
About SSO in Casdoor
When a user who is already signed in to Casdoor opens the sign-in page of another application, Casdoor shows a picker: continue as the current user or use another account. With automatic sign-in, Casdoor skips the picker and signs the current user in.
SSO between applications has three parts:
- Each application has a Home URL.
- Each application has Auto signin turned on.
- The home page of each application implements silent sign-in: when it is opened with the SSO link, it starts the sign-in on its own.