This article is about configuring SSO for your ideas portal. Read these articles if you want to configure SSO for your Aha! Ideas account.
Single sign-on (SSO) allows your users to log in to your ideas portal using OneLogin. With SSO, you can increase engagement of your idea portals as employees and customers no longer need to keep track of yet another email and password.
Click a link to skip to a section:
Add the app in OneLogin
Do not use the Aha! connector in OneLogin to configure SSO for an ideas portal. The Aha! connector supports SSO for the Aha! application only.
In OneLogin, select Applications and then Add app.
Search for and select SAML Custom Connector (Advanced).
Enter a name for the connector, then save it.
Configure the SAML provider in Aha!
You need administrator permissions with customization access to configure portal SSO.
Navigate to Settings → Account → Ideas portals or Ideas → Overview.
-
Open the portal you want to configure.
From Settings → Account → Ideas portals, select the portal name.
From Ideas → Overview, select the pencil icon next to the portal name.
Navigate to Access → Identity provider.
Open the menu and select Add new provider.
Choose SAML from the Type list, then select Save.
Select Manual settings from Settings using.
Copy the SAML entity ID. You will use this value in OneLogin.
Complete configuration in OneLogin
Return to the SSO tab in the OneLogin connector. Use the SAML entity ID from your Aha! Ideas portal’s Access → Identity provider settings to complete the configuration.
Relay state: Leave blank.
Audience (EntityID): Paste the SAML entity ID from Aha!.
Recipient: Paste the SAML entity ID from Aha!.
ACS Consumer URL: Paste the SAML entity ID from Aha!
ACS Consumer URL Validator: Enter a regular expression that matches your ACS Consumer URL exactly. For example:
^https://big.aha.io/ai_redirects?url=eyJ1cmwiOiJodHRwczoiLCJhY2NvdW50X2lkIjoiNTgxMDQwNjkyNjEyMzQxMTk2MCJ9--8d9affbe344b3aa7630312baffb3073165af3612\/\/example-domain\.identity\.aha\.io\/idea_portal_provider\/saml_callback\/1234567890$SAML not valid before: Keep the default value of 5 minutes.
SAML not valid after: Keep the default value of 5 minutes.
SAML Initiator: Select OneLogin.
SAML NameID format: Select Persistent.
SAML Issuer type: Select Specific.
SAML Signature Element: Keep the default value, Assertion.
SAML Session NotOnOrAfter: Keep the default value of 1440 minutes. This sets a 24-hour login session.
Configure user parameters
Open the Parameters tab in OneLogin. OneLogin must send the following attributes for portal SSO to work:
NameID
Email
FirstName
LastName
Map each parameter to the corresponding user value in your OneLogin directory.
Verify your configuration
In OneLogin, Audience (EntityID), Recipient, and ACS Consumer URL use the SAML entity ID from your Aha! Ideas portal.
In Aha!, the Single sign-on endpoint uses the OneLogin SAML 2.0 Endpoint (HTTP).
In Aha!, the Certificate fingerprint uses the OneLogin SHA Fingerprint.
In OneLogin, the connector sends NameID, Email, FirstName, and LastName.
Enable SSO
In OneLogin, copy the SAML 2.0 Endpoint (HTTP).
In your Aha! Ideas portal’s Users → SSO settings, paste the value into Single sign-on endpoint.
In OneLogin, copy the SHA Fingerprint.
In Aha!, paste the value into Certificate fingerprint.
Select Enable SSO.
Aha! Ideas portal user experience
Users sign in to your ideas portal through OneLogin. Users with an active OneLogin session can access the portal without signing in again.
Public portal: Users must sign in before they can submit or vote on ideas. Anyone can view published ideas.
Private portal: Users must sign in through OneLogin before they can access the portal. Any user with an authorized OneLogin account can access the portal, regardless of email domain.
You can invite an ideas portal user who is not yet configured in your identity provider. The user cannot sign in until OneLogin can authenticate them.
Share your SSO configuration between portals (Advanced plan)
If your Aha! account includes Aha! Ideas Advanced, you can create one identity provider configuration and assign it to multiple ideas portals.
Configure the OneLogin connector using the steps in this article.
Navigate to Settings → Account → Ideas portals and organizations or Ideas → Overview.
Open the portal you want to configure, then navigate to Access → Identity provider.
Select Add new provider from the Identity provider list.
Enter a descriptive name for the provider.
Choose SAML as the provider type.
Select Save and continue in Aha!.
Complete the SAML configuration using the values from OneLogin.
Select Enable SSO.
To use the same identity provider in another portal:
Open the portal’s settings and navigate to Access → Identity provider.
Select the identity provider from the Identity provider list.
Repeat these steps for each portal that will use the shared configuration.
Manage identity providers and view the portals that use them from Settings → Account → Ideas portals → Identity providers.
Set contact custom field values
Portal SSO can set idea portal contact custom fields when a user signs in. Your SSO provider (JWT or SAML) sends attributes that map to specific contact custom fields in your Aha! account. Each incoming attribute maps to a contact custom field by its API key and then sets or updates the value on the portal contact. This works for both new and existing portal users.
This capability is useful when you already maintain important user data in your identity provider. You can store an internal user identifier, region, or other key attributes directly on the portal contact. New contacts receive these values at creation. Existing contacts are updated the next time the user signs in, so your Aha! account stays aligned with your source of truth without additional API calls.
To set contact custom field values through portal SSO:
Identify the data you want to sync.
-
Configure custom fields on your contact layout.
Navigate to User menu -> Settings -> Account -> Custom layout.
Edit the contact layout for your account and confirm or create new fields for each attribute you want to sync.
For each field, note the API key exactly as it appears in the configuration. You will use this in your SSO mapping.
-
Map attributes in your SSO identify provider.
Add attributes to the assertion for your portal.
Set each attribute name to match the corresponding contact custom field API key from your Aha! account.
Map each attribute to the correct data source in your identity provider so the value reflects what you want stored in the portal contact.
-
Test with a single user.
Choose a test user in your identity provider and use it to log in to your portal via SSO.
In your Aha! account, open the portal contact record for that user and confirm that the custom fields now contain the expected values.
Troubleshooting
If portal SSO does not work as expected, review the common SSO configuration issues.
Start with the integration log messages for your SSO configuration. These messages identify authentication and configuration errors that can help you find the cause.
If you get stuck, please reach out to our Customer Success team. Our team is made up entirely of product experts and responds fast.