2-key SSO is a special setup of 2-hop SSO useful when the portal cannot resolve complete identity attributes (BigN) after the first hop. It creates a mapping between the external vendor's unique identifier (2-key) and EiMP-identification-requiring BigN. The portal stores this mapping for subsequent SSO attempts.
What is Administrator impersonation (Headless API SSO)?
This allows portal administrators and super users to impersonate HSID users to recreate their experience for troubleshooting. The portal backend calls the Aikyam Impersonation API with the user's identity attributes to receive an assertion. This API is ONLY for impersonation use cases, not user-initiated SSO.
Web SSO V2 enables single sign-on between different HSID-integrated portals without requiring re-authentication. It uses an assertion-based mechanism where one portal redirects to another through the SSO V2 endpoint.