> For the complete documentation index, see [llms.txt](https://help.citrusad.com/retail-media-interface/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://help.citrusad.com/retail-media-interface/integration/hu/feature-integrations/single-sign-on.md).

# Egykattintásos bejelentkezés (SSO) kiskereskedőknek

Epsilon Retail MediaSSO integration allows direct connection to the retailer's IDP via SAML 2.0. This provides retailer users with an SSO login option authenticated by your IDP.

{% hint style="info" %}
Retailer Users Only

As a multi-tenant platform that enables advertisers to access multiple retailer platforms, our capability best suits retailers who want to enforce SSO for internal staff, rather than advertisers.

We do not allow delegated management of the advertiser user lifecycle, as this could impact other retailer platforms.
{% endhint %}

## Capability Scope

Epsilon Retail Media allows the IDP to authenticate when a user accesses your namespace. This is configured on a per-namespace basis. Please note that the platform's SSO capability enables **authentication**, not **authorisation**. Access management for teams is still configured programmatically within the platform.

{% hint style="info" %}
Advertiser Access

Since our platform is a globally connected, multi-tenant platform, advertisers will continue to log in directly through the login module. Advertisers must still be invited to your platform to gain access, even if they have access to other retailer platforms.
{% endhint %}

## Key Information

* This feature is best for retailers who want to manage the lifecycle of internal users, such as secure offboarding of internal staff
* Team and user access must be managed programmatically within the platform, and this is not possible through the SSO integration
* All IDP user support and management must be directed by the retailer.
* The advertiser user lifecycle must remain within the: Epsilon platform. We do not provide delegated authority to offboard advertiser users, as this could impact the advertiser's access to other platforms.

## User Flows

Flows differ for existing and new platform users.

### Existing User Flow

If you implement SSO post-launch, most users already have access to teams and an established account in: Epsilon. Therefore, the process is simpler.

<figure><img src="/files/ludq2HWRPDcmoqVYralV" alt="" width="100%"><figcaption></figcaption></figure>

<br>

### New User Flow

For new users, you must invite every user to the appropriate teams. They must go through the registration process, after which they can authenticate via your SSO IDP for future access.

<figure><img src="/files/Z17CkfYcYW52KHRWZROl" alt="" width="100%"><figcaption></figcaption></figure>

If necessary, they can also log in directly via your SSO IDP, and upon authentication approval, we create a user just in time. The user must still be manually, programmatically invited to their appropriate teams. We recommend inviting users in advance to ensure team access is granted.

<figure><img src="/files/zWK5IsWVWaKauNNXxQgd" alt="" width="100%"><figcaption></figcaption></figure>

<br>

## User Experience

On portals where retailer SSO is integrated, the password field is removed from the initial login screen. If the user enters an email address that connects to your IDP under your retailer domain, the user is automatically redirected to your IDP for authentication.

<figure><img src="/files/qfBeYoYtks6lxbIb9Px3" alt="" width="100%"><figcaption></figcaption></figure>

The forgot password feature is also delegated to the password entry in the next step, as you are responsible for all SSO-related password management.

## Integration Requirements

### IDP Integration

To integrate, Epsilon requires the following:

**From your IDP**

* Entity ID
* SSO URL
* IDP signing certificate

**We also request the following:**

* Custom login help link: this link appears to all users, where you should host a link explaining the login process
* Custom message: a custom message displayed in relation to the custom link
* Custom link label: the label for the custom login help link
* Password reset site name: the site name displayed to users
* Expired password URL: where the IDP redirects links for expired passwords

Epsilon will also configure on the Epsilon page the following information, which we will share with you:

* Entity ID (audience URI)
* Base URL
* ACS URL

These are provided by the: Epsilon team.

### Attribute Mapping

Attributes on the: Epsilon configuration is as follows:

* primary email
* firstName
* lastName
* email

Accordingly, you may need to configure mappings in your IDP.

## Unsupported SSO Features

* User Management\*\*: Epsilon does not support automated user management to add, modify, or remove users. This process requires manual updates in both the Identity Provider (IDP) and the Epsilon.
* **Account Support**: When retailers transition to single sign-on (SSO), Epsilon does not handle user account setup or support. This means, Epsilon does not allow direct login or password resets. All SSO users must contact the retailer for account assistance.
* OAUTH Support\*\*: Epsilon does not support integration using OAuth authentication for services such as [Microsoft Azure Active Directory B2C](https://learn.microsoft.com/en-us/azure/active-directory-b2c/overview). SSO integration is only available with SAML authentication.

## Retailer Owned Platform SSO: Advertiser Account Bridging Solution

If you are a retailer integrating our partners' API capabilities and providing your own front-end to advertisers, we offer a bridging solution for retailers to manage the advertiser lifecycle within your own portals.

The purpose of this feature is also to allow your owned platform to automatically authenticate with the: Epsilonplatform within your own namespace.

### High-Level Overview

This bridging solution involves leveraging existing retailer SSO capabilities, allowing advertiser accounts to be created under your owned domain.

* A kiskereskedő létrehozza a felhasználói fiókot az Identitásszolgáltató (IDP) szolgáltatásán belül. A következők használatával: Epsilon OKTA just in time (JIT) provisioning, ez automatikusan létrehozza a felhasználói fiókot a következőn belül: Epsilon platform.
* A kiskereskedő meghívja a felhasználót a kívánt beszállítói vagy kiskereskedői csapatba a következőkön keresztül: Epsilon csapatkezelési UI. (Enélkül a felhasználó egy üres UI-val szembesül a következőben: Epsilon)
* A felhasználói fióknak rendelkeznie kell a kereskedő által megadott egyedi domain névvel. Az OKTA-n belül több domain név is konfigurálható, például <name@retailer.com>, <name@retailerdomain.com>, <name@retailername.com>

### Megszüntetés

A felhasználók jogosultságainak megszüntetése a következő folyamat szerint történik:

* A kereskedő kivezeti a felhasználói fiókot az IDP-ből.
* A felhasználó nem fog tudni hitelesíteni/bejelentkezni a Epsilon platformra a kereskedő tulajdonában lévő felhasználói e-mail-címmel.
  * A felhasználó továbbra is képes lesz hitelesíteni/bejelentkezni más kereskedelmi platformokra a rendes hirdetői e-mail-címével
* A felhasználói fiók továbbra is létezni fog a Epsilon rendszerben, azonban 90 napos tétlenség után az Életciklus-kezelési (Life Cycle Management) folyamat deaktiválja a fiókjukat.
* Ha a felhasználói fiókot újraaktiválják az IDP-ben, a megfelelő felhasználói fiók a Epsilon rendszerben is aktiválásra kerül.
* Ha a kereskedő megköveteli a felhasználó teljes eltávolítását a Epsilon rendszerből, akkor manuálisan el kell távolítani őket azokból a csapatokból, amelyekbe meghívták őket a platformon belül.

### Korlátozások

* Ez nem tartja karban az igazi hirdető fiókjának életciklusát, hanem egy duplikált, izolált felhasználót hoz létre a hirdető számára az Ön kereskedői domainje alatt. Ez potenciális zavart okozhat a hirdető számára.\\
  * <jane.doe@sodapopco.com> felhasználó marad a Epsilon platformon, hozzáféréssel az összes csapathoz több kereskedőnél. <jane.doe.sodapopco@retailer.com> kezelése Ön által, a kereskedő által történik az Ön tulajdonában lévő domain alatt
* Ez az áthidaló megoldás fenntartja a Nem támogatott SSO-funkciók részben ismertetett korlátozásokat, amelyben a kereskedőnek kell kezelnie a fiókkonfigurációt, a támogatást, valamint a felhasználói/csapathozzáférést.
* Minden felhasználói támogatást és kezelést a kereskedőnek kell lebonyolítania.

## GYIK

* Mi történik, ha nem hívok meg valakit a csapataiba, de SSO-n keresztül jelentkezik be?
  * Ha a felhasználó nem létezik, de SSO-n keresztül jelentkezik be, egy üres képernyő fogadja mindaddig, amíg meg nem hívja a csapatokba.
* Van bármilyen mód a csapat-/felhasználói hozzáférés SSO-val vagy API-val történő kezelésére?
  * Nem, ez jelenleg nem lehetséges, és manuálisan, a felhasználói felületen (UI) keresztül kell kezelni.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://help.citrusad.com/retail-media-interface/integration/hu/feature-integrations/single-sign-on.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
