1. Self-Hosting
  2. Single Sign-On
  3. Configure Single Sign-On
  • Home
  • What is TileDB?
  • Get Started
  • Explore Content
  • Accounts
    • Individual Accounts
      • Apply for the Free Tier
      • Profile
        • Overview
        • Cloud Credentials
        • Storage Paths
        • REST API Tokens
        • Credits
    • Organization Admins
      • Create an Organization
      • Profile
        • Overview
        • Members
        • Cloud Credentials
        • Storage Paths
        • Billing
      • API Tokens
    • Organization Members
      • Organization Invitations
      • Profile
        • Overview
        • Members
        • Cloud Credentials
        • Storage Paths
        • Billing
      • API Tokens
  • Catalog
    • Introduction
    • Data
      • Arrays
      • Tables
      • Single-Cell (SOMA)
      • Genomics (VCF)
      • Biomedical Imaging
      • Vector Search
      • Files
    • Code
      • Notebooks
      • Dashboards
      • User-Defined Functions
      • Task Graphs
      • ML Models
    • Groups
    • Marketplace
    • Search
  • Collaborate
    • Introduction
    • Organizations
    • Access Control
      • Introduction
      • Share Assets
      • Asset Permissions
      • Public Assets
    • Logging
    • Marketplace
  • Analyze
    • Introduction
    • Slice Data
    • Multi-Region Redirection
    • Notebooks
      • Launch a Notebook
      • Usage
      • Widgets
      • Notebook Image Dependencies
    • Dashboards
      • Dashboards
      • Streamlit
    • Preview
    • User-Defined Functions
    • Task Graphs
    • Serverless SQL
    • Monitor
      • Task Log
      • Task Graph Log
  • Scale
    • Introduction
    • Task Graphs
    • API Usage
  • Structure
    • Why Structure Is Important
    • Arrays
      • Introduction
      • Quickstart
      • Foundation
        • Array Data Model
        • Key Concepts
          • Storage
            • Arrays
            • Dimensions
            • Attributes
            • Cells
            • Domain
            • Tiles
            • Data Layout
            • Compression
            • Encryption
            • Tile Filters
            • Array Schema
            • Schema Evolution
            • Fragments
            • Fragment Metadata
            • Commits
            • Indexing
            • Array Metadata
            • Datetimes
            • Groups
            • Object Stores
          • Compute
            • Writes
            • Deletions
            • Consolidation
            • Vacuuming
            • Time Traveling
            • Reads
            • Query Conditions
            • Aggregates
            • User-Defined Functions
            • Distributed Compute
            • Concurrency
            • Parallelism
        • Storage Format Spec
      • Tutorials
        • Basics
          • Basic Dense Array
          • Basic Sparse Array
          • Array Metadata
          • Compression
          • Encryption
          • Data Layout
          • Tile Filters
          • Datetimes
          • Multiple Attributes
          • Variable-Length Attributes
          • String Dimensions
          • Nullable Attributes
          • Multi-Range Reads
          • Query Conditions
          • Aggregates
          • Deletions
          • Catching Errors
          • Configuration
          • Basic S3 Example
          • Basic TileDB Cloud
          • fromDataFrame
          • Palmer Penguins
        • Advanced
          • Schema Evolution
          • Advanced Writes
            • Write at a Timestamp
            • Get Fragment Info
            • Consolidation
              • Fragments
              • Fragment List
              • Consolidation Plan
              • Commits
              • Fragment Metadata
              • Array Metadata
            • Vacuuming
              • Fragments
              • Commits
              • Fragment Metadata
              • Array Metadata
          • Advanced Reads
            • Get Fragment Info
            • Time Traveling
              • Introduction
              • Fragments
              • Array Metadata
              • Schema Evolution
          • Array Upgrade
          • Backends
            • Amazon S3
            • Azure Blob Storage
            • Google Cloud Storage
            • MinIO
            • Lustre
          • Virtual Filesystem
          • User-Defined Functions
          • Distributed Compute
          • Result Estimation
          • Incomplete Queries
        • Management
          • Array Schema
          • Groups
          • Object Management
        • Performance
          • Summary of Factors
          • Dense vs. Sparse
          • Dimensions vs. Attributes
          • Compression
          • Tiling and Data Layout
          • Tuning Writes
          • Tuning Reads
      • API Reference
    • Tables
      • Introduction
      • Quickstart
      • Foundation
        • Data Model
        • Key Concepts
          • Indexes
          • Columnar Storage
          • Compression
          • Data Manipulation
          • Optimize Tables
          • ACID
          • Serverless SQL
          • SQL Connectors
          • Dataframes
          • CSV Ingestion
      • Tutorials
        • Basics
          • Ingestion with SQL
          • CSV Ingestion
          • Basic S3 Example
          • Running Locally
        • Advanced
          • Scalable Ingestion
          • Scalable Queries
      • API Reference
    • AI & ML
      • Vector Search
        • Introduction
        • Quickstart
        • Foundation
          • Data Model
          • Key Concepts
            • Vector Search
            • Vector Databases
            • Algorithms
            • Distance Metrics
            • Updates
            • Deployment Methods
            • Architecture
            • Distributed Compute
          • Storage Format Spec
        • Tutorials
          • Basics
            • Ingestion & Querying
            • Updates
            • Deletions
            • Basic S3 Example
            • Running Locally
          • Advanced
            • Versioning
            • Time Traveling
            • Consolidation
            • Distributed Compute
            • RAG LLM
            • LLM Memory
            • File Search
            • Image Search
            • Protein Search
          • Performance
        • API Reference
      • ML Models
        • Introduction
        • Quickstart
        • Foundation
          • Basics
          • Storage
          • Cloud Execution
          • Why TileDB for Machine Learning
        • Tutorials
          • Ingestion
            • Data Ingestion
              • Dense Datasets
              • Sparse Datasets
            • ML Model Ingestion
          • Management
            • Array Schema
            • Machine Learning: Groups
            • Time Traveling
    • Life Sciences
      • Single-cell
        • Introduction
        • Quickstart
        • Foundation
          • Data Model
          • Key Concepts
            • Data Structures
            • Use of Apache Arrow
            • Join IDs
            • State Management
            • TileDB Cloud URIs
          • SOMA API Specification
        • Tutorials
          • Data Ingestion
          • Bulk Ingestion Tutorial
          • Data Access
          • Distributed Compute
          • Basic S3 Example
          • Multi-Experiment Queries
          • Appending Data to a SOMA Experiment
          • Add New Measurements
          • SQL Queries
          • Running Locally
          • Shapes in TileDB-SOMA
          • Drug Discovery App
        • Spatial
          • Introduction
          • Foundation
            • Spatial Data Model
            • Data Structures
          • Tutorials
            • Spatial Data Ingestion
            • Access Spatial Data
            • Manage Coordinate Spaces
        • API Reference
      • Population Genomics
        • Introduction
        • Quickstart
        • Foundation
          • Data Model
          • Key Concepts
            • The N+1 Problem
            • Architecture
            • Arrays
            • Ingestion
            • Reads
            • Variant Statistics
            • Annotations
            • User-Defined Functions
            • Tables and SQL
            • Distributed Compute
          • Storage Format Spec
        • Tutorials
          • Basics
            • Basic Ingestion
            • Basic Queries
            • Export to VCF
            • Add New Samples
            • Deleting Samples
            • Basic S3 Example
            • Basic TileDB Cloud
          • Advanced
            • Scalable Ingestion
            • Scalable Queries
            • Query Transforms
            • Handling Large Queries
            • Annotations
              • Finding Annotations
              • Embedded Annotations
              • External Annotations
              • Annotation VCFs
              • Ingesting Annotations
            • Variant Statistics
            • Tables and SQL
            • User-Defined Functions
            • Sample Metadata
            • Split VCF
          • Performance
        • API Reference
          • Command Line Interface
          • Python API
          • Cloud API
      • Biomedical Imaging
        • Introduction
        • Foundation
          • Data Model
          • Key Concepts
            • Arrays
            • Ingestion
            • Reads
            • User Defined Functions
          • Storage Format Spec
        • Quickstart
        • Tutorials
          • Basics
            • Ingestion
            • Read
              • OpenSlide
              • TileDB-Py
          • Advanced
            • Batched Ingestion
            • Chunked Ingestion
            • Machine Learning
              • PyTorch
            • Napari
    • Files
  • API Reference
  • Self-Hosting
    • Installation
    • Upgrades
    • Administrative Tasks
    • Image Customization
      • Customize User-Defined Function Images
      • AWS ECR Container Registry
      • Customize Jupyter Notebook Images
    • Single Sign-On
      • Configure Single Sign-On
      • OpenID Connect
      • Okta SCIM
      • Microsoft Entra
  • Glossary

On this page

  • Claim rewriting
    • Configuration file
  • On-Behalf-Of Flow
    • Configuration file
  1. Self-Hosting
  2. Single Sign-On
  3. Configure Single Sign-On

Configure Single Sign-On

administration
single sign-on (sso)
Learn how to enable OpenID Connect SSO providers.

In TileDB Cloud Self-Hosted, it is possible to use configuration values to enable OpenID Connect (OIDC) single sign-on (SSO). Enabling one or more SSO providers allows TileDB Cloud Self-Hosted to use an existing identity management provider.

To configure SSO for your TileDB Cloud Self-Hosted installation, add the following to your values.yaml file, filling in your specific SSO details in the OIDC key:

# This configuration contains the necessary values to enable Single Sign-On (SSO) for
# Company integration with TileDB Cloud. By configuring these settings, the OpenID
# Connect (OIDC) component of the TileDB Cloud Rest Server is activated, thereby
# facilitating SSO both in the TileDB Cloud UI and the backend services. Customize
# the SSO parameters by replacing the placeholder values listed below with your
# specific SSO details. Pass these values alongside `values.yaml` to enable SSO
tiledb-cloud-rest:
  restConfig:
    SSO:
      OIDC: [] # List of SSO OIDC configurations. Replace placeholders with SSO details.
      # Example configuration:
      # - Domain: <SSO_Domain>
      #   OIDCIssuer: <SSO_OIDC_Issuer_URL>
      #   OIDCClientID: <SSO_Client_ID>
      #   OIDCClientSecret: <SSO_Client_Secret>

tiledb-cloud-ui:
  config:
    # This enables the toggle
    EnableCompanySSO: true # Enable SSO for the TileDB Cloud UI.

Claim rewriting

If your OpenID Connect implementation doesn’t provide data in the necessary format, you can configure TileDB Cloud to rewrite the claims to get what it needs. This is configured by setting the ClaimMapping key for the specific OIDC entry to {"target": "template string with {other}"}, where target is the claim to which TileDB will write the data, and template string with {other} is a string where the text {other} will be replaced by the other claim in the source claims.

In this case, performing the above substitution on an OpenID Connect token with the following claims:

{ "claim1": "example", "other": "data" }

will result in the addition of a target claim:

{ "claim1": "example", "other": "data", "target": "template string with data" }

For instance, if the OIDC claim doesn’t include an email, but it does include a preferred_username claim with a bare username, you can configure the substitution:

{ "email": "{preferred_username}@mycompany.example" }

This will transform a token like:

{ "iss": "some_issuer", "sub": "some_sub", "preferred_username": "the-user" }

into

{
  "iss": "some_issuer",
  "sub": "some_sub",
  "preferred_username": "the-user",
  "email": "the-user@mycompany.example"
}

Alternately, if your preferred_username field is already a full email address, you can omit the suffix:

{ "email": "{preferred_username}" }

Configuration file

You can customize these parameters by replacing the example values listed below with details for your specific SSO service’s OpenID Connect configuration.

# The tiledb-cloud-rest.restConfig.SSO.OIDC field contains server-side configuration
# to allow users to log in with SSO.
tiledb-cloud-rest:
  restConfig:
    SSO:
      # The "OIDC" key is a list of OpenID Connect configurations,
      # one for each email domain.
      OIDC:
        - Domain: mycompany.example
          OIDCIssuer: https://sso.mycompany.example/oidc-issuer
          OIDCClientID: tiledb-client-id
          OIDCClientSecret: tiledb-client-secret
          ClaimMapping: { "email": "{preferred_username}@mycompany.example" }
          # If you have users logging in with more than one email domain,
          # you can use multiple OpenID Connect configurations.
          # They may use the same issuer or a different one, as needed.
        - Domain: subsidiary.example
          OIDCIssuer: https://sso.mycompany.example/subsidiary-login
          OIDCClientID: other-client-id
          OIDCClientSecret: other-client-secret
          # If the ClaimMapping entry is missing, the claims are not modified.
# Setting tiledb-cloud-ui.config.EnableCompanySSO shows the "Corporate SSO" button
# in the TileDB Cloud web login screen.
tiledb-cloud-ui:
  config:
    EnableCompanySSO: true

On-Behalf-Of Flow

The On-Behalf-Of (OBO) Flow is a scenario in OAuth 2.0 where a client application (middle-tier service) uses an access token obtained through another OAuth flow (e.g., Authorization Code Flow or Client Credentials Flow) to call another web API (downstream service) on behalf of the original user.

TileDB Cloud supports using Microsoft identity platform and OAuth 2.0 On-Behalf-Of flow to provide tokens that can be used from TileDB Cloud API clients to access REST server with a scope of *.

Configuration file

Customize these parameters by replacing the example values listed below with details for your specific OBO configuration.

tiledb-cloud-rest:
  restConfig:
    SSO:
      OnBehalfOfToken:
        Audience: <aud JWT field>
        Issuer: https://login.microsoftonline.com/<TenantID>/v2.0
        TenantID: <TenantID>
        IntegrationType: Microsoft
Single Sign-On
OpenID Connect