Help Center

SSO Integrations Changelog

This page is the changelog for SSO Integrations, in reverse chronological order. The most recent update is highlighted at the top, followed by the history grouped by period.

July 2026

You can now set a client-secret expiry date and get warned before it lapses, PingFederate joins the built-in providers, and connection setup and testing get clearer.

Keeping a connection healthy

  • You can now set a client-secret expiry date when you save a connection. Altana reminds the people who manage SSO 30 days out, warns everyone signing in 7 days out, and marks the connection with a red status once the secret expires — so a lapsed secret never surprises you.
  • You can rotate an expiring secret in place with Update Secret: paste the new secret and set its new expiry date. Your IdP registration, Redirect URI, and group mappings stay exactly as they are.

Provider support

  • PingFederate is now a built-in provider preset, alongside Generic OIDC, Microsoft Entra ID, and Okta.

Testing and verification

  • A connection is now verified automatically the first time someone signs in through it successfully, so activating without a separate test step is safe.
  • After a test sign-in, the Claims Inspector shows the exact claims your IdP returned, including the real group values, so you can fill in your group mappings from live data.

Setting up a connection

  • New in-product guidance walks you through registering a dedicated app for Altana and mapping its groups.
  • After activation, the Client Secret and its expiry stay editable while the Discovery URL and provider are locked — routine secret rotation never puts the rest of the connection at risk.

June 2026

Self-service SSO arrives: configure an OpenID Connect identity provider yourself, map your groups, test before going live, and keep bypass users who can always sign in.

Setting up a connection

  • You can now set up single sign-on yourself from Settings → SSO against any OpenID Connect identity provider, with no Altana engineering involved.

Group mapping

  • You can map your IdP groups to Altana groups from a claim in the sign-in token, and set a default group for users who don't match any mapping.

Testing and verification

  • You can test a connection with a real sign-in before you turn it on, so you confirm it works without locking anyone out.

Access safeguards

  • You can designate SSO Bypass users who can always sign in without SSO — a safeguard while you configure or troubleshoot a connection.
  • Turning on SSO doesn't remove your organization's existing sign-in, and password reset is blocked for SSO users unless they're bypass users.