m3ter Single Sign-On - m3ter Documentation

m3ter Single Sign-On (SSO)

m3ter Single Sign-On (SSO) allows users with federated identities that exist in different Identity Providers (IdPs) to sign into m3ter without having to manually provision new users/identities in m3ter’s user pool. m3ter SSO supports SAML-based Identity Providers (IdPs). The SAML 2.0 standard offers an XML-based protocol for the exchange of user security information, such as authentication and authorization details, between an identity provider and service provider. In this way, SAML enables the implementation of web-based SSO across security domains.

To implement SSO, two main steps are required:

When SSO has been implemented for your chosen SAML-based IdP, you might have to check how your users will be provisioned. This topic explains how SSO is implemented in m3ter for your chosen IdP and how to authenticate and log into the m3ter Console when your corporate federated identity has been set up:

Setting Up an External Identity Provider

Here are the settings you’ll need when setting up your external IdP.

SSO URL/Endpoint

This is the Single Sign-On URL/Endpoint where the m3ter application receives the SAML assertion:

https://m3ter.auth.us-east-1.amazoncognito.com/saml2/idpresponse

Audience URI

This is the Entity ID of the m3ter application:

urn:amazon:cognito:sp:us-east-1_9OJBvIFUw

Attributes Mappings

The following table gives the mappings between the identity attributes used in the external provider and the ones used by m3ter that must be also configured:

External IdP Attribute m3ter Attribute
<> name*
<> email*
<> firstName
<> lastName
<> groups

Notes:

Setting Up an Identity Provider in m3ter

An Identity Provider can be created in m3ter for a single m3ter Organization or for all of the m3ter Organizations you use:

User Provisioning for SSO

Depending on how and when your IdP setup for m3ter SSO was implemented and other factors, such as the possibility of pre-existing m3ter users, you might have to check to ensure your users are properly provisioned for SSO inclusion and have the correct permissions assigned to them. Here are some explanatory notes and recommendations to help with this:

Using SSO to Sign Into the m3ter Console

When your corporate federated identity has been set up for SSO, you can use it to authenticate and sign into the m3ter Console.

Coming Soon: IdP-Initiated Logins! IdP-initiated logins are not currently supported but will be added in the future. If you’re interested in this feature, please get in touch with m3ter Support or your m3ter contact.

To authenticate with the platform:

  1. Open your browser and enter the URL for the m3ter environment. The m3ter Sign in to your account appears. The default presentation is for User/Password authentication:

  2. Instead, select Single Sign-On (SSO). The sign in adjusts for SSO and Sign in with Single Sign-On (SSO) using your Corporate ID shows:

  3. Enter your federated SSO corporate Email Address to authenticate and gain access to the Console:

    • If your account has been set up for access to a single Organization, you are taken directly to the m3ter Console Dashboard for the Organization.
    • If your account had been set up for access to more than one Organization, a Select Organization page opens. Select the Organization you want to access. The meter Console Dashboard for the selected Organization opens.

Important! When you log in to the m3ter platform for the first time, please review our Terms of Service straightaway to ensure you accept them. To review these terms, click the Documentation link at the bottom of the Console’s main navigation, and then select Legal.