Setting up Single Sign-On (SSO)
Connect NINJIO Secure Code to your identity provider using the secure setup link we sent you. We've sent your IT administrator a personal SSO setup link. It opens a guided, self-service wizard that connects NINJIO Secure Code to your organisation's identity provider — Microsoft Entra ID (Azure AD), Okta, Google Workspace, or any OIDC provider. You stay in full control: you never share your secret or password with us. Setup usually takes 15–20 minutes.
1.Before you begin
- Admin access to your identity provider (Entra ID, Okta or
- Google Workspace).
- The setup link we emailed you — valid for 5 days and up to 10 opens.
- 15–20 minutes without interruption (the wizard has a short
- active session).
- A colleague to help test a sign-in at the end (optional but
Please note: once SSO is switched on, your people sign in
through your identity provider — username-and-password sign-in
is turned off, so it's best to complete setup in one sitting.
2.What you'll do in the wizard
- Open the setup link and choose your identity provider from the list.
- Create an app (registration) in your identity provider, following the on-screen instructions.
- Exchange the values. Copy the values the wizard shows into your provider and paste your provider's values back — including your Client ID and Client Secret.
- Map the email attribute so each user's email flows to NINJIO Secure Code (it's how we match people).
- Assign your users / groups to the app in your provider.
- Test & finish — use the wizard's Test button, then sign in at the NINJIO Secure Code login page.
3. Avoid the common snags
- ENTRA ID: Send the Secret Value, not the Secret ID. Entra shows three fields — Application (client) ID, Secret ID, and Secret Value. You need the client ID and the secret Value. The Value is shown only once when you create it, so copy it straight away; if you've navigated away, create a new secret.
- REDIRECT URI: Use the exact callback URL the wizard displays. Add it to your app's allowed redirect URIs. If it's missing you'll see errors such as AADSTS50011 (redirect URI mismatch).
- ENTRA ID: Grant admin consent. A Global Administrator may need to approve the sign-in app in Enterprise applications → Permissions → Grant admin consent.
- SIGN-IN: Start at the NINJIO Secure Code login page, not from the Microsoft "My Apps" tile — sign-in must begin on our side, not your provider's app launcher.
- LINK LIMITS: Don't let the link expire. 5 days / 10 opens. Retrying too many times can use them up — if it stops working, just ask us for a fresh link.
4 Keeping SSO working — secret renewals
- Your identity provider's client secret expires after a set period (for many organisations, once a year). This isn't a setup error — it's how your provider is configured. When it expires, all of your users will be locked out until it's renewed
- Get ahead of it: ask your IT team to set a calendar reminder before the expiry date. When the time comes, generate a new secret in your provider, then let us know — we'll send you an update link so you can apply the new value yourself.
- (Requesting or opening an update link doesn't disrupt anything; the change only takes effect once you enter the new value.)
Questions, a new link, or a renewal?
Get in touch for a fresh setup link, an update link when your
secret is due to expire, or any SSO help.
Contact: support@ninjio.com
NINJIO Secure Code login: securecode.goninjio.com
Comments
0 comments
Please sign in to leave a comment.