Document version

Version Date Auteur Description
v1.0 05/04/2024 Florent Martinier Initial document
v1.1 03/09/2026 Gautier Levert Add account provisioning, domain routing and first login. Remove vendor name. Group the guides in a section.

We can delegate the authorization of users to any Single Sign-on (SSO) solution supporting at least one of the following protocol:

Account provisioning

The platform does not create accounts. A user who signs in without an existing Sopht account is denied and sees an error page.

Sopht creates the accounts beforehand. Declare every new person to your Sopht contact before their first login.

Routing by email domain

A user types their email address on the Sopht login page. Its domain decides which SSO receives the request.

An address outside the declared domains is not routed to your SSO. Tell us about any new domain, merger or subcontractor address.

First login

On their first login, a user receives an email titled “Confirm your identity”. They click its link to finish linking their account.

The link is valid for 30 minutes. Past that delay, the user starts the login again.

Configuration guides

The Azure page walks through the setup step by step. The OpenID Connect page lists what any provider has to send us.

Azure

OpenID Connect