Configure SAML SSO to Kensho
Let your users sign in to Kensho with your organization's identity provider (IdP) over SAML 2.0. Kensho works with any SAML 2.0 IdP.
Supported features
- SP-initiated SSO: sign-in starts from Kensho.
- IdP-initiated SSO: sign-in starts from a Kensho tile in your IdP dashboard.
- Just-In-Time (JIT) provisioning: a matching Kensho account is created on first sign-in.
Prerequisites
Before you configure SAML 2.0 for Kensho, you need the following:
- Administrator access to your IdP.
- The corporate email domain(s) that your users sign in with (for example,
@example.com). Kensho routes sign-ins to your org by matching this domain. - An SSO ID and Audience URI for your account, provided by the Kensho support team (see below).
Configuration steps
Contact the Kensho support team (support@kensho.com), request SAML 2.0 SSO, and include your corporate email domain(s). Kensho provisions the connection on its side and sends you an SSO ID and Audience URI to use below.
Select your identity provider.
- In the Okta Admin Console, go to Applications → Applications.
- Click Browse App Catalog.
- Search for and select the Kensho app.
- Click Add Integration.
- On the General Settings tab, enter the SSO ID and Audience URI from Kensho, then click Next.
- On the Sign-On Options tab, select SAML 2.0, then click Done to finish adding the integration.
- On the Sign On tab, under Metadata details, copy the Metadata URL.
- On the Assignments tab, assign the users and groups who need access to Kensho. Only assigned users can sign in.
Then complete the connection with Kensho:
- Send your Metadata URL to the Kensho support team (support@kensho.com).
- Kensho activates the connection.
Your SAML configuration for Kensho is complete. Kensho creates each user's account on their first sign-in (JIT provisioning).
SAML attributes
Your IdP sends the following attributes to Kensho, which Kensho uses to create each user. In the Okta integration, they are preconfigured, so you don't need to add them.
| Name | Value |
|---|---|
email | user.email |
firstName | user.firstName |
lastName | user.lastName |
Roles
If you want different groups of users to receive different entitlements, send a
division attribute. You choose the values and how each user's division is set. For
example, investment-banking and asset-management users could receive different
entitlements. Share your planned values with Kensho ahead of time, and Kensho maps each one
to the right entitlements.
Use short identifiers without spaces (letters, digits, hyphens, or underscores). Kensho matches the values you send against the ones you shared, so a value that doesn't match won't grant any entitlements.
SP-initiated SSO
The sign-in process is initiated from Kensho.
- From your browser, navigate to kensho.okta.com (opens in a new tab) or sign in to any Kensho application.
- Enter your corporate email address and continue.
- You are redirected to your IdP, authenticate there, and are then redirected back to Kensho.
Troubleshoot
For help configuring or debugging a connection, contact the Kensho support team at support@kensho.com.