# OpenID

[![Snímek obrazovky 2024-04-23 142722.png](https://doc.eainfoport.cz/uploads/images/gallery/2024-04/scaled-1680-/snimek-obrazovky-2024-04-23-142722.png)](https://doc.eainfoport.cz/uploads/images/gallery/2024-04/snimek-obrazovky-2024-04-23-142722.png)

- "*Active*" tells us if we want Infoport to work with OpenID.
- "Login using OpenId Groups relations only" it is possible to set a ban on the login of a user who does not have an OpenID group assigned.

***Server Realm*** – fill in the link to the open id server

*For Microsoft Entra ID: In Endpoints, find the Authority URL item (Accounts in this organizational directory only).*

[![image-1665479608966.png](https://doc.eainfoport.cz/uploads/images/gallery/2022-10/scaled-1680-/image-1665479608966.png)](https://doc.eainfoport.cz/uploads/images/gallery/2022-10/image-1665479608966.png)

- - - - - -

***Metadata*** – fill in the link to the open id server metadata

*For Microsoft Entra ID: In Endpoints, find the OpenID Connect metadata document item*

[![image-1665479593158.png](https://doc.eainfoport.cz/uploads/images/gallery/2022-10/scaled-1680-/image-1665479593158.png)](https://doc.eainfoport.cz/uploads/images/gallery/2022-10/image-1665479593158.png)

- - - - - -

***ClientID*** – fill in the reference to the Client identifier

*For Microsoft Entra ID: In Essentials, find the Application (client) ID item*

[![image-1665479977551.png](https://doc.eainfoport.cz/uploads/images/gallery/2022-10/scaled-1680-/image-1665479977551.png)](https://doc.eainfoport.cz/uploads/images/gallery/2022-10/image-1665479977551.png)

- - - - - -

***Client Secret*** – insert client secret

*For Microsoft Entra ID: The administrator must generate it in Essentials / Client credentials / **Value***

[![image-1665479962615.png](https://doc.eainfoport.cz/uploads/images/gallery/2022-10/scaled-1680-/image-1665479962615.png)](https://doc.eainfoport.cz/uploads/images/gallery/2022-10/image-1665479962615.png)

- - - - - -

***Redirect Uri*** – enter the url that will be called after logging out of the infoport

*For Microsoft Entra ID:*

[![image-1665479987025.png](https://doc.eainfoport.cz/uploads/images/gallery/2022-10/scaled-1680-/image-1665479987025.png)](https://doc.eainfoport.cz/uploads/images/gallery/2022-10/image-1665479987025.png)

- - - - - -

***Infoport Group for Portals Admins*** – enter the name of the group where you want the Infoport portal administrator users to be

*For Microsoft Entra ID:*

[![image-1665480000658.png](https://doc.eainfoport.cz/uploads/images/gallery/2022-10/scaled-1680-/image-1665480000658.png)](https://doc.eainfoport.cz/uploads/images/gallery/2022-10/image-1665480000658.png)

- - - - - -

***LogoutUri*** – enter a url that logs out of open id

*For Microsoft Entra ID:*

[![image-1665480018624.png](https://doc.eainfoport.cz/uploads/images/gallery/2022-10/scaled-1680-/image-1665480018624.png)](https://doc.eainfoport.cz/uploads/images/gallery/2022-10/image-1665480018624.png)

- - - - - -

***Claim that belongs to the username*** – specify a claim by which the infoport will pull the infoport username from the response

[![image-1665480031495.png](https://doc.eainfoport.cz/uploads/images/gallery/2022-10/scaled-1680-/image-1665480031495.png)](https://doc.eainfoport.cz/uploads/images/gallery/2022-10/image-1665480031495.png)

- - - - - -

***Claim that belongs to the email*** – specify a claim by which the infoport will pull the email from the response

[![image-1665480040204.png](https://doc.eainfoport.cz/uploads/images/gallery/2022-10/scaled-1680-/image-1665480040204.png)](https://doc.eainfoport.cz/uploads/images/gallery/2022-10/image-1665480040204.png)

- - - - - -

***Claim that belongs to the forename*** – specify a claim by which the infoport will pull the user's first name from the response

[![image-1665480049916.png](https://doc.eainfoport.cz/uploads/images/gallery/2022-10/scaled-1680-/image-1665480049916.png)](https://doc.eainfoport.cz/uploads/images/gallery/2022-10/image-1665480049916.png)

- - - - - -

***Claim that belongs to the surname*** – specify a claim by which the infoport will pull the user's last name from the response

[![image-1665480059247.png](https://doc.eainfoport.cz/uploads/images/gallery/2022-10/scaled-1680-/image-1665480059247.png)](https://doc.eainfoport.cz/uploads/images/gallery/2022-10/image-1665480059247.png)

- - - - - -

***Claim that belongs to the groups*** – specify a claim according to which the infoport will pull the groups to which the user belongs from the response

[![image-1665480067373.png](https://doc.eainfoport.cz/uploads/images/gallery/2022-10/scaled-1680-/image-1665480067373.png)](https://doc.eainfoport.cz/uploads/images/gallery/2022-10/image-1665480067373.png)

- - - - - -

Add ***Open ID Scopes***,to return all necessary attributes

<div class="pointer-container" id="bkmrk-%C2%A0-0"><div class="pointer anim is-page-editable"><svg class="svg-icon" data-icon="link" role="presentation" viewbox="0 0 24 24" xmlns="http://www.w3.org/2000/svg"></svg><div class="input-group inline block"><input id="bkmrk--26" placeholder="url" readonly="readonly" type="text"></input> <button class="button outline icon" data-clipboard-target="#pointer-url" title="Kopírovat odkaz" type="button"><svg class="svg-icon" data-icon="copy" role="presentation" viewbox="0 0 24 24" xmlns="http://www.w3.org/2000/svg"></svg></button></div><svg class="svg-icon" data-icon="edit" role="presentation" viewbox="0 0 24 24" xmlns="http://www.w3.org/2000/svg"></svg></div></div>[![image-1665480078281.png](https://doc.eainfoport.cz/uploads/images/gallery/2022-10/scaled-1680-/image-1665480078281.png)](https://doc.eainfoport.cz/uploads/images/gallery/2022-10/image-1665480078281.png)

Other related information about OpenID:

[https://doc.eainfoport.cz/books/user-manual/page/mapping-a-group-to-openid](https://doc.eainfoport.cz/books/user-manual/page/mapping-a-group-to-openid)

[https://doc.eainfoport.cz/books/user-manual/page/login-of-a-user-who-does-not-have-an-openid-group-assigned](https://doc.eainfoport.cz/books/user-manual/page/login-of-a-user-who-does-not-have-an-openid-group-assigned)

[https://doc.eainfoport.cz/books/question-answer/page/missing-repository-permissions-during-ad-or-openid-login](https://doc.eainfoport.cz/books/question-answer/page/missing-repository-permissions-during-ad-or-openid-login)