Documentation
Enterprise IdentitySAML 2.0 & OIDCRFC 7644 SCIM 2.0Pillar 4.1

Enterprise SSO & SCIM 2.0 Directory Sync

Centralize authentication across your enterprise, eliminate password fatigue, and automate team lifecycle management with native SAML 2.0, OpenID Connect (OIDC), and RFC 7644 SCIM 2.0 provisioning for Okta, Microsoft Entra ID (Azure AD), and PingFederate.

Identity Architecture

Zero-Friction Domain Discovery

When an employee enters their corporate work email (e.g., john.smith@bechtel.com), Forge automatically queries /api/identity/sso/discover, detects their managed tenant, and renders an instant one-click SSO redirect button.

SAML 2.0 & OIDC Assertion Engine

Native deflation, Base64 decoding, and XML assertion processing powered by fast-xml-parser. Extracts Subject NameID and email claims, validates cryptographic status codes, and establishes secure session cookies.

Automated SCIM 2.0 Directory Sync

Certified RFC 7643 / RFC 7644 endpoints (/api/scim/v2/Users, /ServiceProviderConfig, /Schemas). Okta and Azure AD automatically provision new hires, update department roles, and trigger instant account suspensions.

Soft De-provisioning (Evidence Protection)

When an employee is offboarded in Okta or Azure AD, SCIM DELETE or PATCH active: false transitions their environment status to SUSPENDED rather than hard-deleting the record, preserving contemporaneous audit logs and cryptographic evidence trails.

Configuration Guide

Environment Owners and Claims Managers can configure Enterprise SSO in seconds via /dashboard/settings:

1Choose an Identity Provider Preset

Select Okta, Microsoft Entra ID, or PingFederate to pre-populate recommended SAML/OIDC metadata templates.

2Bind Corporate Domain & Endpoints

Specify your email domain (e.g., skanska.com), your IdP Issuer/Entity ID URL, and your IdP Single Sign-On Login URL.

3Copy Service Provider Endpoints into Your IdP

Paste the Assertion Consumer Service (ACS) URL (.../api/identity/sso/saml/acs/:configId) and SP Entity ID / Audience URI into your Okta or Azure AD application configuration.

4Configure SCIM 2.0 Automated Directory Sync

Copy your environment's SCIM 2.0 Base URL and Bearer Token(API Key) into your IdP's Provisioning tab. Users and roles will immediately synchronize with Forge.

© 2026 Forge Project Intelligence. All rights reserved.