> For the complete documentation index, see [llms.txt](https://docs.peakcommerce.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.peakcommerce.com/product/using-peakcommerce/authentication-and-security/what-will-our-web-team-need-to-do-over-and-above-the-sso-setup.md).

# What Your Web Team Needs for SSO

This page covers the technical handshake your web or identity team performs **once** to connect enterprise (staff) SSO. It assumes you have already decided to enable SSO with your PeakCommerce implementation team — see [Single Sign-On for PeakCommerce Sites](/product/using-peakcommerce/authentication-and-security/single-sign-on-for-peakcommerce-sites.md) for the bigger picture.

## What PeakCommerce needs from you

To connect your **OpenID Connect (OIDC)** provider, the implementation team needs:

* **Issuer URL** — the base URL of your provider, used to fetch its OIDC discovery document.
* **Client ID** — the application/client identifier PeakCommerce will present.
* **Client secret** — supplied securely; it is stored only by reference and never exposed in the admin UI.

## What your team configures on your IdP

Allow-list this exact **callback (redirect) URL** in your OIDC application:

```
https://<subdomain>.auth0.com/login/callback
```

PeakCommerce uses a single canonical callback host (callback URLs are exact-match allow-listed, never one per tenant subdomain), so register the value the implementation team gives you verbatim. If a branded custom login domain is in use, the implementation team will tell you whether the callback should reference that domain instead.

## Good to know

* **Identity only.** PeakCommerce reads `sub`, `email`, and `name` from the token. Group, role, and permission claims are ignored — access is granted inside PeakCommerce by [role](/product/using-peakcommerce/users-and-user-roles/user-roles.md) and [profile](/product/using-peakcommerce/profiles-and-permissions/user-profile-overview.md), so your IdP cannot raise a user's privileges.
* **Logout.** If you want sign-out to also clear the session at your IdP, register your post-logout return URL with the implementation team as well.
* **Customer portal SSO is a separate setup.** The signed-token handoff that signs *end customers* into the portal is configured differently from staff OIDC — see [Single Sign-On for PeakCommerce Sites](/product/using-peakcommerce/authentication-and-security/single-sign-on-for-peakcommerce-sites.md).

## Related

* [Single Sign-On for PeakCommerce Sites](/product/using-peakcommerce/authentication-and-security/single-sign-on-for-peakcommerce-sites.md)
* [Login Pages](/product/using-peakcommerce/authentication-and-security/types-of-login-pages-for-your-peakcommerce-account.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.peakcommerce.com/product/using-peakcommerce/authentication-and-security/what-will-our-web-team-need-to-do-over-and-above-the-sso-setup.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
