Optimizely - SSO Configuration

Optimizely - SSO Configuration

Alert
This application has not been formally tested by Kelvin Zero Inc. It is provided solely as a reference guide. If you encounter any issues, kindly submit a ticket directly through the support desk.
Quote
This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Optimizely using Multi-Pass. SSO simplifies user authentication by allowing access to multiple applications with a single set of credentials. This integration enhances security and improves user experience across your organization.
Warning
To configure Multi-Pass SSO with Optimizely, ensure you meet the following requirements:
- Optimizely Administrator access
- MPAS Admin rights
- All users intended to use SSO in Optimizely must be registered in your IdP and have the necessary permissions.
Important: Custom elements in URLs (like tenant names or unique strings) are case sensitive. Match the exact casing from your environment.





Optimizely - SSO Configuration






Step 1 - Obtain a Certificate File from Multi-Pass

  • Open Multi-Pass Dashboard
  • Select the correct tenant and go to Integrations, then click on Applications.
  • Select SAML in the custom integration section.

  • Under Tenant Certificate, toggle the first box to Crt and click Download.

  • Save the file locally for later use.

Step 2 - Configure Optimizely as the Service Provider (SP)

  • Log into your Opti ID as an Administrator.
  • Navigate to Settings > SSO > Add SSO Connection > SAML.
  • Complete the fields based on the table below:
Field Value
Connection Name KZero Multi-Pass SSO
Issuer URL / Entity ID https://ca.auth.kzero.com/realms/<TENANT_NAME>
SSO URL https://ca.auth.kzero.com/realms/<TENANT_NAME>/protocol/saml
  • Under Signature Certificate, click Select file… and upload the .crt file obtained in Step 1.
  • Click Save.
  • Copy the Audience URL and Assertion Consumer Service URL from the SSO Connection Details section and save them for use in Step 3.

Step 3 - Configure Multi-Pass as the Identity Provider (IdP)

  • Open Multi-Pass Dashboard
  • Select the correct tenant and go to Integrations, then click on Applications.
  • Select SAML in the custom integration section and complete the setup with the table below.


Field Value
Client ID (=SP Entity ID)Unique String provided in Step 2
Nameoptimizely
DescriptionOptimizely SSO integration
Assertion Consumer Service URLhttps://login.optimizely.com/sso/saml2/<UNIQUE_STRING>
NameID Policy Formatemail

  • Click Add Integration
  • Browse to the Advanced Console by clicking on the left side of your screen

  • Click Clients and search for Optimizely.
  • Ensure all fields match the settings below.
General settings (Multi-Pass)
FieldValue
Client IDUnique String provided in Step 2
Nameoptimizely
DescriptionOptimizely SSO integration
Always display in UION
Access settings (Multi-Pass)
FieldValue
Home URL (IdP-initiated)https://ca.auth.kzero.com/realms/<TENANT_NAME>/protocol/saml/clients/<APP_NAME>
Valid Redirect URIs (ACS)https://login.optimizely.com/sso/saml2/<UNIQUE_STRING>
IDP-Initiated SSO URL Name<APP_NAME>
SAML Capabilities
SettingValue
Name ID Formatemail
Force Name ID FormatON
Force POST BindingON
Include AuthnStatementON
Signature & Encryption
SettingValue
Sign DocumentsOFF
Sign AssertionsON
  • Go to the Keys tab and ensure both parameters are set to OFF.

    • Related Articles

    • D2L Brightspace - SSO Integration

      This application has not been formally tested by Kelvin Zero Inc. It is provided solely as a reference guide. If you encounter any issues, kindly submit a ticket directly through the support desk. This documentation provides a step-by-step guide to ...
    • Mulesoft - SSO Integration

      This application has been formally tested by Kelvin Zero Inc. This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Mulesoft using Multi-Pass. SSO simplifies user authentication by allowing access to multiple ...
    • SAML SSO Integration Guide

      This guide provides an overview of how to configure SAML Single Sign-On (SSO) between Multi-Pass and a third-party Service Provider (SP). Multi-Pass acts as the Identity Provider (IdP) in this federation model. Multi-Pass is working on SCIM support ...
    • Miro - SSO configuration

      This documentation has been tested and approved by Kelvin Zero's team This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Miro using MPAS. SSO simplifies user authentication by allowing access to multiple ...
    • Pipedrive – SSO configuration

      This application has been formally tested by Kelvin Zero Inc. This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Pipedrive using Multi-Pass. SSO simplifies user authentication by allowing access to multiple ...