Data privacy notice

 

When this content is loaded, usage information is transmitted to Vimeo and may be processed there.

 

             

OpenID Connect

Modified on Mon, 14 Aug, 2023 at 4:48 PM

The OpenID Connect login service can be used to connect an OpenID Connect identity provider to formcycle. The OpenID Connect specific configuration options are described below. For general information on basic settings and creating login services, see Login Services.


Contents


Configuration

Configuration options for an OpenID Connect identity provider.


Client ID

Unique ID of the configuration that is provided by the identity provider.


Client secret

Secret key which is used to authenticate your client.


Discovery URI

URI which is used to determine the properties of the identity provider. It has to be provided by the identity provider.


Scope

Specifies the permissions that are used by formcycle when querying fields from the identity provider.


Authentication method

Method by which formcycle authorizes itself to the identity provider.


Response type

Type of response from the identity providers after formcycle logon.


Extended settings

Advanced settings for configuring an OpenID Connect identity provider.

By clicking on Extended settings additional parameters for the connection with the identity provider can be configured.


Response mode

Method by which the identity provider sends the logon respone to formcycle.


Max. authentication lifetime (seconds)

Maximum duration of an exisitng login to the identity provider. The default value is -1, which means infinite.


Connection Timeout (seconds)

Maximum duration for a connection setup to the indentity provider before it is terminated. The default value is 500 seconds.


Max. clock skew (seconds)

Maximum allowed difference in system clock times between the  formcycle Server and the identity provider. The default value is 30 seconds.


Expire session with token

Setting that specifies whether a formcycle logon should also expire when the identity provider logon expires. This option is disabled by default.


Token expiration advance (seconds)

Time period that a FORMCYCLE logon should expire before the identity provider token. The default value is 0 seconds.


Further parameters

In addition to the ones listed above, other parameters can be defined in this table. A property and a corresponding value must be entered in each line.

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article