Logging In with Single Sign-On
How this works depends on:
- Whether this is the first-time login and the subscriber does not yet have a corresponding IDI Customer Portal account.
- Whether the subscriber is already logged in with OpenID Connect credentials.
- The subscriber’s Customer Portal profile Force Single Sign-On setting.
Note: Corporate account browsing is not impacted by single sign-on.
First Time Login
If the subscriber is accessing the IDI Customer Portal for the first time and their identity is not yet linked to a Customer Portal account, the system will automatically create an account for them. The system will check if their organizational identity is already linked to a Customer Portal account. If no link is found, the system will create a new Customer Portal account using information from their organizational identity. The incoming identity must have a value provided in the Customer Account Claim parameter as set up in the Security module Authorization Provider configuration. The subscriber will then be automatically logged into the IDI Customer Portal.
Subscriber Already Logged in with OpenID Connect Credentials
If the subscriber is navigating from the external application and is already logged with the OpenID Connect provider credentials, they’ll be automatically redirected to the IDI Customer Portal without having to re-enter credentials regardless of the Force Single Sign-On setting.
Force Single Sign On Enabled
In this case, the standard IDI Customer Portal Login page is not available. If the subscriber is not yet logged in with OpenID Connect credentials, they will first be redirected to your organization’s login page and then redirected to the IDI Customer Portal upon successful login.

Force Single Sign On Not Enabled
In this case, subscribers who are not yet logged in with OpenID Connect credentials will have the option to either log in with their IDI Customer Portal credentials or continue with your organization’s login and use their OpenID Connect credentials.

Logging Out
The Customer Portal provides a Log Out option for subscribers authenticated via OpenID Connect. How this works depends on the Force Single Sign-Out parameter as set up in the Security module Authorization Provider configuration:
- If Force Single Sign-Out is enabled, the subscriber will be redirected to your organization's sign-out page.
- If Force Single Sign-Out is not enabled, the subscriber will be signed out of the Customer Portal and shown a confirmation page.
Error Handling During Login
The system will display a clear error message if an issue occurs during the single sign-on process. This message provides information on why the login failed.
