Authentication methods

FoxIDs authenticates users through authentication methods. You can use the built-in login experience, trust external identity providers with OpenID Connect, SAML 2.0, or WS-Federation, connect FoxIDs environments, and support token exchange or an existing user store.

Application registrations use authentication methods to sign users in. See Applications for how apps and APIs connect to FoxIDs.

FoxIDs authentication methods and application registrations

Take a look at the FoxIDs test connections in FoxIDs Control: https://control.foxids.com/test-corp
Sign in with the reader email address and password shown on the sign-in page for read-only access.

Create an authentication method

In FoxIDs Control, select the Authentication tab and click Add authentication. The first selection shows the standard OpenID Connect and SAML 2.0 connections and available quick-setup templates.

Enable Show all options when you need an advanced type such as the built-in login UI, WS-Federation, Environment Link, token exchange, or External API Login. Select a type, configure the connection, and click Create.

Authentication method types

The available authentication method categories are:

For two-factor and multi-factor scenarios, see Two-factor and multi-factor authentication (2FA/MFA).

Authentication method session

Each authentication method creates its own session when a user authenticates. There are two session types:

  • Login authentication methods create a user session.
  • OpenID Connect, SAML 2.0, and WS-Federation authentication methods create an authentication method session that stores the data required to continue the login flow and perform logout.

Both session types support configuring lifetime, absolute lifetime, and persistence.

Connect external identity providers

An external OpenID Provider (OP), Identity Provider (IdP), or Security Token Service (STS) can be connected with an OpenID Connect, SAML 2.0, or WS-Federation authentication method.

All IdPs supporting either OpenID Connect, SAML 2.0, or WS-Federation can be connected to FoxIDs. The following are common integration guides.

OpenID Connect

Configure OpenID Connect to trust an external OpenID Provider.

Always request the sub claim, even if you only plan to use the email claim or another custom user ID claim.

How-to guides:

SAML 2.0

Configure SAML 2.0 to trust an external Identity Provider.

Always request the NameID claim, even if you primarily use the email (http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress) claim or another custom user ID claim. SAML 2.0 logout requires NameID.
Prefer metadata-driven configuration so the customer's IdP can automatically download certificate(s). When possible, ask the customer for a live IdP metadata endpoint.

How-to guides:

WS-Federation

Configure WS-Federation to trust an external Security Token Service (STS) / Identity Provider.

Prefer metadata-driven configuration when the STS exposes Federation Metadata. It lets FoxIDs read endpoints, token type, and signature validation certificates automatically.

Common platforms include AD FS, Microsoft Entra ID legacy WS-Federation applications, SharePoint, Dynamics, and generic WS-Federation STSes.

Connect FoxIDs environments

FoxIDs environments can be connected in two ways:

Environment Link is the fastest and simplest option, but it only works inside one tenant.
OpenID Connect takes more configuration, but it works across tenants and deployments.

Verified platforms

List of customer-verified platforms.

Try the test tenant

FoxIDs cloud is configured with the test tenant test-corp, which contains multiple connected authentication methods.

Your Privacy

Your Privacy

We use cookies to make your experience of our websites better. Click the 'Accept all cookies' button to agree to the use of cookies. To opt out of non-essential cookies, click 'Necessary cookies only'.

Visit our Privacy Policy page for more