SSO and integration

Last update:
Aug 24, 2026
  1. What types of SSO does HSID support?
    Three types:
    • Web SSO: SSO among portals (Portal A to Portal B)
    • Inbound SSO: SSO from external vendors to portals (2-hop, 1-hop, or 2-key methods)
    • Outbound SSO: SSO from portals to external vendors
  2. What is 2-key SSO and when should I use it?
    2-key SSO is a special setup of 2-hop SSO useful when the portal cannot resolve complete identity attributes (BigN) after the first hop. It creates a mapping between the external vendor's unique identifier (2-key) and EiMP-identification-requiring BigN. The portal stores this mapping for subsequent SSO attempts.
  3. What is Administrator impersonation (Headless API SSO)?
    This allows portal administrators and super users to impersonate HSID users to recreate their experience for troubleshooting. The portal backend calls the Aikyam Impersonation API with the user's identity attributes to receive an assertion. This API is ONLY for impersonation use cases, not user-initiated SSO.
  4. What is Aikyam web SSO V2?
    Web SSO V2 enables single sign-on between different HSID-integrated portals without requiring re-authentication. It uses an assertion-based mechanism where one portal redirects to another through the SSO V2 endpoint.
    Reference : Web SSO

On this page

Powered by Aikyam @2025 All rights reserved