Connect your identity provider

Technical reference for registering Microsoft Entra ID, Salesforce Marketing Cloud or another OAuth 2.0 provider for Studio sign-in.

4 min read

For your IT team or identity administrator: what to register in your provider, and what to send back. The admin view is in Company sign-in (SSO).

Your Customer Success Manager turns SSO on

You don't configure SSO yourself. Your Customer Success Manager gives you the exact callback URL to register in your provider. Once you've shared the details below, they enable the provider for your environment.

How sign-in works

Sign-in uses the OAuth 2.0 Authorization Code flow. Microsoft Entra ID uses OpenID Connect on top of it. Salesforce Marketing Cloud and other providers use plain OAuth 2.0, with a user info endpoint.

  1. The user selects the provider button on the sign-in page.
  2. OmniLab redirects them to the provider's authorization endpoint.
  3. The provider authenticates the user and redirects back to OmniLab's callback URL.
  4. OmniLab exchanges the authorization code for tokens at the token endpoint.
  5. OmniLab reads the user's identity from the user info endpoint.
  6. If a Studio account has that email and an organisation, sign-in completes.

Microsoft Entra ID

Register the application

  1. In the Azure portal, register a new application under App registrations.
  2. Under Supported account types, choose Accounts in this organizational directory only.
  3. Under Authentication, add a Redirect URI (platform: Web) with the callback URL you were given.
  4. Under Certificates & secrets, create a Client secret.
  5. Copy the secret's value. It's shown only once.
  6. Note the secret's expiry date.
  7. On the Overview tab, note the Application (client) ID and Directory (tenant) ID.

A client secret lasts 24 months at most. Send your Customer Success Manager a new one before it expires: when it lapses, nobody can sign in with Entra ID.

Details to share with OmniLab

FieldWhere to find itNotes
Application (client) IDAzure portal > App registrations > OverviewIdentifies your Entra app
Directory (tenant) IDAzure portal > App registrations > OverviewLimits sign-in to your Microsoft tenant
Client secret valueAzure portal > Certificates & secrets (shown once)Lets OmniLab complete the code exchange
Button display nameYour choiceWhat users see on the sign-in page
Callback URL registeredConfirm onlyThe OmniLab URL must appear in the Redirect URIs list

Scopes: openid, email, profile (standard OIDC). Sign-in needs no other permissions.

OmniLab finds the Studio account by the email Entra ID returns: the user's mail address, which isn't always their sign-in name. A user without one is refused with Email required. Sign in with a test user to check the address comes through.

Salesforce Marketing Cloud

Create the package

  1. In Marketing Cloud, open Setup > Apps > Installed Packages.
  2. Select New.
  3. Name the package.
  4. Select Add Component.
  5. Choose API Integration.
  6. Choose Web App.
  7. Add the callback URL you were given as a Redirect URI.
  8. Save the component.
  9. Note the Client ID and Client Secret.
  10. Note the package's Authentication Base URI, such as https://<subdomain>.auth.marketingcloudapis.com/.

Details to share with OmniLab

The three URLs add a path to your authentication base URI.

FieldNotes
Client IDIdentifies your package
Client secretLets OmniLab complete the code exchange, sent in the request body
Authorization URLhttps://<subdomain>.auth.marketingcloudapis.com/v2/authorize
Token URLhttps://<subdomain>.auth.marketingcloudapis.com/v2/token
User info URLhttps://<subdomain>.auth.marketingcloudapis.com/v2/userinfo. Must return the user's email: that's how OmniLab finds their Studio account
Callback URL registeredConfirm only

Marketing Cloud requests no OAuth scopes: access follows the package's own permissions.

Another OAuth 2.0 provider

Ask your Customer Success Manager before you plan this: one custom provider can be added per environment. Gather:

FieldNotes
Button display nameWhat users see on the sign-in page
Client IDIdentifies your provider application
Client secretSent in the token request body (client_secret_post)
Authorization URLYour provider's authorization endpoint
Token URLYour provider's token endpoint
User info URLMust return the user's email
Scope stringThe scopes your provider needs to return the email
Callback URL registeredThe OmniLab callback URL must be in the provider's allowed redirect list

Before you launch

  • The provider application is registered, with the OmniLab callback URL in its allowed redirect list.
  • Secrets were shared securely with your Customer Success Manager, never in a plain-text email.
  • At least one test user exists in OmniLab and is assigned to an organisation.
  • The test user's email in OmniLab exactly matches the email the provider returns.
  • You've confirmed which environment the provider is enabled for: Staging or Production.

Next steps

On this page