Skip to content

Sign-in across products

Every TinyBlox product signs people in through one identity provider, with OpenID Connect. Signed in once, a person opens any other console without signing in again: the identity provider remembers them.

When
TinyGuard You want the platform to bring its own: tenants, multifactor sign-in, sign-in through Google or another provider, and setup by the provisioner. See the TinyGuard guide.
Keycloak You already run it. The provisioner supports it as well.
Microsoft Entra ID, Okta, others You already run them. Register each product’s clients by hand (how); the provisioner’s support for Entra ID and Okta is planned.

Whatever the provider, each product needs:

  • a client for its console, with the product’s redirect address (https://<console address>/auth/callback for TinyConductor);
  • the groups and roles of the person in the token, in the groups and roles claims, so the product can give them their rights.

Each product has its own roles, for example admin, operator and viewer in TinyConductor. Who holds them is decided per environment: give roles to groups once, for every product, in the access file, or in your identity provider’s console. Each product’s guide lists its roles and how it maps groups to them.

A product that serves several customers or teams keeps them apart as tenants. Across products the same tenant has the same name: TinyConductor’s tenant acme reads its secrets from TinyVault’s tenant acme.

When a person or service may act in more than one tenant, it names the tenant on every API call in the header X-Tenant-Id. A call without it is refused rather than given a default tenant. TinyConductor works this way today; the other products follow coming.

coming Each console will show an Apps button in its top bar, listing the other consoles of the environment that this person may open:

┌ Apps ──────────────────────────┐
│ ◆ TinyConductor Current │
│ ◆ TinyVault │
└────────────────────────────────┘
  • Only what you may open. A console you have no access to is not listed. Who may open which console is set per environment, as any of a list of roles or groups, in the environment file.
  • No second sign-in. Choosing a console opens it already signed in, through the identity provider’s existing session. If that session has ended, the provider asks you to sign in, as it would anyway.
  • Any OpenID Connect provider. The list comes from your environment, not from the provider, so it works with TinyGuard, Keycloak, Entra ID, Okta or your own.

The details are still being settled; this section will grow when the first release with the switcher is listed on Release status.