Skip to main content

Version: latest

SSO for Dashboard

API7 Dashboard supports Single Sign-On (SSO) to centralize user management and improve security. By integrating with your corporate identity provider (IdP), users can log in to the dashboard using their existing credentials, eliminating the need for separate dashboard accounts.

Supported Protocols

ProtocolDescriptionCommon Providers
OIDCOpenID Connect, a modern OAuth 2.0-based protocolKeycloak, Microsoft Entra ID, Auth0, Okta
SAMLSAML 2.0, an XML-based federation protocolMicrosoft Entra ID, Okta, Ping Identity, ADFS
LDAPLightweight Directory Access Protocol, direct directory authenticationOpenLDAP, Microsoft Active Directory, FreeIPA
CASCentral Authentication ServiceApereo CAS

Key Capabilities

  • Multiple Login Options: Configure multiple SSO providers simultaneously. Users see all enabled options on the login page.
  • Automatic Role Mapping: Map IdP attributes (user fields, group memberships) to API7 roles, synchronized on each login.
  • Permission Boundary Mapping: Automatically assign permission policies based on IdP attributes.
  • Built-in Login: The built-in username/password login option can coexist with SSO providers or be disabled.
note

At least one login option must remain enabled at all times. You cannot delete or disable the last remaining enabled option.

Choosing a Protocol

  • Use OIDC if your IdP supports it — it is the most widely adopted modern SSO protocol and offers the simplest integration.
  • Use SAML if your organization requires SAML 2.0 federation (common in enterprises with Microsoft Entra ID or Okta).
  • Use LDAP if you need to authenticate directly against a directory service without browser redirects (e.g., for environments where only CLI or programmatic access is available).

Getting Started

  1. Configure SSO with OIDC — Recommended for most deployments.
  2. Configure SSO with SAML — For SAML 2.0 federation requirements.
  3. Configure SSO with LDAP — For direct directory authentication.

Additional Resources

API7.ai Logo

The digital world is connected by APIs,
API7.ai exists to make APIs more efficient, reliable, and secure.

Sign up for API7 newsletter

Product

API7 Gateway

SOC2 Type IIISO 27001HIPAAGDPRRed Herring

Copyright © APISEVEN PTE. LTD 2019 – 2026. Apache, Apache APISIX, APISIX, and associated open source project names are trademarks of the Apache Software Foundation