Connect your identity provider
Technical reference for registering Microsoft Entra ID, Salesforce Marketing Cloud or another OAuth 2.0 provider for Studio sign-in.
For your IT team or identity administrator: what to register in your provider, and what to send back. The admin view is in Company sign-in (SSO).
Your Customer Success Manager turns SSO on
You don't configure SSO yourself. Your Customer Success Manager gives you the exact callback URL to register in your provider. Once you've shared the details below, they enable the provider for your environment.
How sign-in works
Sign-in uses the OAuth 2.0 Authorization Code flow. Microsoft Entra ID uses OpenID Connect on top of it. Salesforce Marketing Cloud and other providers use plain OAuth 2.0, with a user info endpoint.
- The user selects the provider button on the sign-in page.
- OmniLab redirects them to the provider's authorization endpoint.
- The provider authenticates the user and redirects back to OmniLab's callback URL.
- OmniLab exchanges the authorization code for tokens at the token endpoint.
- OmniLab reads the user's identity from the user info endpoint.
- If a Studio account has that email and an organisation, sign-in completes.
Microsoft Entra ID
Register the application
- In the Azure portal, register a new application under App registrations.
- Under Supported account types, choose Accounts in this organizational directory only.
- Under Authentication, add a Redirect URI (platform: Web) with the callback URL you were given.
- Under Certificates & secrets, create a Client secret.
- Copy the secret's value. It's shown only once.
- Note the secret's expiry date.
- On the Overview tab, note the Application (client) ID and Directory (tenant) ID.
A client secret lasts 24 months at most. Send your Customer Success Manager a new one before it expires: when it lapses, nobody can sign in with Entra ID.
Details to share with OmniLab
| Field | Where to find it | Notes |
|---|---|---|
| Application (client) ID | Azure portal > App registrations > Overview | Identifies your Entra app |
| Directory (tenant) ID | Azure portal > App registrations > Overview | Limits sign-in to your Microsoft tenant |
| Client secret value | Azure portal > Certificates & secrets (shown once) | Lets OmniLab complete the code exchange |
| Button display name | Your choice | What users see on the sign-in page |
| Callback URL registered | Confirm only | The OmniLab URL must appear in the Redirect URIs list |
Scopes: openid, email, profile (standard OIDC). Sign-in needs no other permissions.
OmniLab finds the Studio account by the email Entra ID returns: the user's mail address, which isn't always their sign-in name. A user without one is refused with Email required. Sign in with a test user to check the address comes through.
Salesforce Marketing Cloud
Create the package
- In Marketing Cloud, open Setup > Apps > Installed Packages.
- Select New.
- Name the package.
- Select Add Component.
- Choose API Integration.
- Choose Web App.
- Add the callback URL you were given as a Redirect URI.
- Save the component.
- Note the Client ID and Client Secret.
- Note the package's Authentication Base URI, such as
https://<subdomain>.auth.marketingcloudapis.com/.
Details to share with OmniLab
The three URLs add a path to your authentication base URI.
| Field | Notes |
|---|---|
| Client ID | Identifies your package |
| Client secret | Lets OmniLab complete the code exchange, sent in the request body |
| Authorization URL | https://<subdomain>.auth.marketingcloudapis.com/v2/authorize |
| Token URL | https://<subdomain>.auth.marketingcloudapis.com/v2/token |
| User info URL | https://<subdomain>.auth.marketingcloudapis.com/v2/userinfo. Must return the user's email: that's how OmniLab finds their Studio account |
| Callback URL registered | Confirm only |
Marketing Cloud requests no OAuth scopes: access follows the package's own permissions.
Another OAuth 2.0 provider
Ask your Customer Success Manager before you plan this: one custom provider can be added per environment. Gather:
| Field | Notes |
|---|---|
| Button display name | What users see on the sign-in page |
| Client ID | Identifies your provider application |
| Client secret | Sent in the token request body (client_secret_post) |
| Authorization URL | Your provider's authorization endpoint |
| Token URL | Your provider's token endpoint |
| User info URL | Must return the user's email |
| Scope string | The scopes your provider needs to return the email |
| Callback URL registered | The OmniLab callback URL must be in the provider's allowed redirect list |
Before you launch
- The provider application is registered, with the OmniLab callback URL in its allowed redirect list.
- Secrets were shared securely with your Customer Success Manager, never in a plain-text email.
- At least one test user exists in OmniLab and is assigned to an organisation.
- The test user's email in OmniLab exactly matches the email the provider returns.
- You've confirmed which environment the provider is enabled for: Staging or Production.
Next steps
- SSO launch checklist
- About SSO for your team
- Authentication: server-to-server API access, a separate setup