Digital Developer Conference: a FREE half-day online conference focused on AI & Cloud – North America: Nov 2 – India: Nov 9 – Europe: Nov 14 – Asia Nov 23 Register now

Close outline
  • United States
IBM?
  • Site map
IBM?
  • Marketplace

  • Close
    Search
  • Sign in
    • Sign in
    • Register
  • IBM Navigation
IBM Developer Answers
  • Spaces
    • Blockchain
    • IBM Cloud platform
    • Internet of Things
    • Predictive Analytics
    • Watson
    • See all spaces
  • Tags
  • Users
  • Badges
  • FAQ
  • Help
Close

Name

Community

  • Learn
  • Develop
  • Connect

Discover IBM

  • ConnectMarketplace
  • Products
  • Services
  • Industries
  • Careers
  • Partners
  • Support
10.190.13.195

Refine your search by using the following advanced search options.

Criteria Usage
Questions with keyword1 or keyword2 keyword1 keyword2
Questions with a mandatory word, e.g. keyword2 keyword1 +keyword2
Questions excluding a word, e.g. keyword2 keyword1 -keyword2
Questions with keyword(s) and a specific tag keyword1 [tag1]
Questions with keyword(s) and either of two or more specific tags keyword1 [tag1] [tag2]
To search for all posts by a user or all posts with a specific tag, start typing and choose from the suggestion list. Do not use a plus or minus sign with a tag, e.g., +[tag1].
  • Ask a question

Bluemix SSO Service - End to end flow for external OAuth providers

270006VMW8 gravatar image
Question by jim.smith001  (16) | Jan 08, 2015 at 06:48 AM ssoibmcloudoauth

Hello, I see that the new version of SSO Service now features ability to sign on with FB, Google etc.

After quickly going through the example code, it seems that the SSO Service is acting as the proxy and the application need not directly interact with end OAuth providers, say facebook.

Just trying to understand the end to end flow for OAuth requests all the way from bluemix client app, SSO Service and the external OAuth servers ( Auth and resource ). Is this available somewhere ?

If my app (mobile app) is just using facebook API, would it be easier to achieve this via simple javascript/ajax ? Would there be any additional benefits of routing external OAuth requests through SSO Service ?

Also, is the SSO currently limited only for Google / FB / IBM Or it is generic enough to use any external OAuth provider ? An example or high level approach would be really appreciated .

Thanks

Alvin Richardson

People who like this

  1
Comment
10 |3000 characters needed characters left characters exceeded
  • Viewable by all users
  • Viewable by moderators
  • Viewable by moderators and the original poster

1 reply

  • Sort: 
110000R98V gravatar image

Answer by Shane Weeden (455) | Jan 17, 2015 at 04:22 PM

You are correct in that the SSO service acts as a proxy - from one or more configured "identity sources" to a common OpenID Connect consumption model for Bluemix applications. Your application need only act as an OpenID Connect client to your SSO service instance.

Any OAuth relationship with a social provider is between the social provider and the SSO service instance. There is a separate OAuth/OpenID Connect relationship between the SSO service instance acting as an authorizaiton server and your application acting as a client.

If your mobile app wants to use the facebook API, the SSO service is not going to help - you need access to facebook access tokens and your app will have to be a direct client to the facebook graph API.

Today the Single Sign On service is designed for BROWSER SSO interactions, using OpenID Connect as the exposed technology for consuming applicaitons. It has the ability to configure any SAML IDP, an in-cloud user registry, or direct links with only Facebook, Google and LinkedIn. It does not provide access tokens from those Social IDPs for the use of OIDC clients.

Comment

People who like this

  0   Share
10 |3000 characters needed characters left characters exceeded
  • Viewable by all users
  • Viewable by moderators
  • Viewable by moderators and the original poster

Follow this question

38 people are following this question.

Answers

Answers & comments

Related questions

How to force login only with Bluemix, using oAuth... 1 Answer

sending email using sendgrid 0 Answers

How to do the Single-Sign-Off from SSO OAUTH in Bluemix app? 2 Answers

Is it possible to validate the access token using any end point? Or can we add custom attributes values to the response access token? 0 Answers

Single Sign On error trying to create the service on Bluemix 1 Answer

  • Contact
  • Privacy
  • IBM Developer Terms of use
  • Accessibility
  • Report Abuse
  • Cookie Preferences

Powered by AnswerHub

Authentication check. Please ignore.
  • Anonymous
  • Sign in
  • Create
  • Ask a question
  • Spaces
  • API Connect
  • Analytic Hybrid Cloud Core
  • Application Performance Management
  • Appsecdev
  • BPM
  • Blockchain
  • Business Transaction Intelligence
  • CAPI
  • CAPI SNAP
  • CICS
  • Cloud Analytics
  • Cloud Automation
  • Cloud Object Storage
  • Cloud marketplace
  • Collaboration
  • Content Services (ECM)
  • Continuous Testing
  • Courses
  • Customer Experience Analytics
  • DB2 LUW
  • Data and AI
  • DataPower
  • Decision Optimization
  • DevOps Build
  • DevOps Services
  • Developers IBM MX
  • Digital Commerce
  • Digital Experience
  • Finance
  • Global Entrepreneur Program
  • Hadoop
  • Hybrid Cloud Core
  • Hyper Protect
  • IBM Cloud platform
  • IBM Design
  • IBM Forms Experience Builder
  • IBM Maximo Developer
  • IBM StoredIQ
  • IBM StoredIQ-Cartridges
  • IIDR
  • ITOA
  • InformationServer
  • Integration Bus
  • Internet of Things
  • Kenexa
  • Linux on Power
  • LinuxONE
  • MDM
  • Mainframe
  • Messaging
  • Node.js
  • ODM
  • Open
  • PartnerWorld Developer Support
  • PowerAI
  • PowerVC
  • Predictive Analytics
  • Product Insights
  • PureData for Analytics
  • Push
  • QRadar App Development
  • Run Book Automation
  • Search Insights
  • Security Core
  • Storage
  • Storage Core
  • Streamsdev
  • Supply Chain Business Network
  • Supply Chain Insights
  • Swift
  • UBX Capture
  • Universal Behavior Exchange
  • UrbanCode
  • WASdev
  • WSRR
  • Watson
  • Watson Campaign Automation
  • Watson Content Hub
  • Watson Marketing Insights
  • dW Answers Help
  • dW Premium
  • developerWorks Sandbox
  • developerWorks Team
  • Watson Health
  • More
  • Tags
  • Questions
  • Users
  • Badges