Skip to content
English
  • There are no suggestions because the search field is empty.

Token-Based/Multipass SSO

How to configure Token-Based/Multipass

Path: Workspace Homepage >> Navigation Panel >> Settings >> Security >> Authentication >> Single Signon

What is Token-Based/Multipass SSO?
Token-Based/Multipass SSO is a Single Sign-On method that allows an organization to share its user authentication with IdeaScale through an encrypted token, passed either in the URL or as a parameter in a POST form.

Token-Based/Multipass SSO is one of the Single Sign-On types available from Single Signon Settings, alongside SAML 2.0 and Azure AD. Configuring it establishes a token-based connection between IdeaScale and the organization's user directory, with a Multipass Site Key and a Multipass API Key serving as the connection's key items.


Role Permissions

  1. Workspace Administrator: Configures the Token-Based/Multipass connection between IdeaScale and the organization's user directory, including the Multipass Site Key, Multipass API Key, and Multipass General Settings.
  2. Community Administrator: Can enable or disable the SSO set up by the Workspace Administrator, for their comunity.
  3. Member: Authenticates through the organization's Token-Based/Multipass connection once it is enabled for the workspace, rather than logging in with separate IdeaScale credentials.


Configure Token-Based/Multipass Single Sign-On

  1. From Single Signon Settings, Single Sign-On (SSO) is switched on if not already enabled, and Add SSO is selected.Screenshot 2025-08-22 at 9-29-02 AM-png-1
  2. Multipass Token is selected from the list of available Single Sign-On types.
  3. IdeaScale's Multipass Site Key and Multipass API Key are entered into the organization's own database.
    multipass token copy

Multipass General Settings

  1. Display Name: A name that identifies this Single Sign-On connection within IdeaScale; any name can be used (e.g., "My Company's Multipass SSO") (TO BE VERIFIED — the source's example name references SAML in this Multipass Token context).
  2. SSO Login URL: The Single Sign-On login page to which members are redirected.
  3. Logout Success URL: The Single Sign-On logout page to which members are redirected.
  4. Blocked Email Domains: Email domains that are not permitted to log in through this connection (e.g., gmail.com).
  5. Enabled: Checked to enable the Token-Based/Multipass connection.
  6. Debugging: Checked to enable the SSO Debugger for this connection.

Note: Enabling the SSO Debugger is recommended, as it is a useful tool for catching Single Sign-On issues.

The Enabled switch must be turned on for the Token-Based/Multipass connection to take effect.


Frequently Asked Questions

What are the Multipass Site Key and Multipass API Key used for?

The Multipass Site Key and Multipass API Key are the key items used to establish the encrypted-token connection between IdeaScale and the organization's own database.

Is the SSO Debugger required to use Token-Based/Multipass SSO?

No. Enabling the SSO Debugger is optional but recommended, since it is a useful tool for catching Single Sign-On issues.

Does the Token-Based/Multipass connection need to be enabled separately from adding it?

Yes. In addition to entering the Multipass Site Key, Multipass API Key, and Multipass General Settings, the Enabled switch must be turned on for the connection to take effect.

Which email addresses are affected by Blocked Email Domains?

Any email address belonging to a domain listed in Blocked Email Domains is not permitted to log in through the Token-Based/Multipass connection.


Related Articles

 

Last Updated: August 16, 2026