Single Sign-On

Choose between Ad Server SSO for your media owner users and Console SSO for your advertiser users.

Kevel has two SSO integrations, and which one applies depends on who is signing in: your own users, or the advertisers using your Console instance.

  • Ad Server SSO is for your media owner users. It covers every way they sign in, both directly to the Kevel Ad Server and through the "Log in as media owner" link on your Console sign-in page.
  • Console SSO is for your advertiser users. It signs them in to your Console instance through your identity provider, instead of a Console password.

Both authenticate against your identity provider (IdP). The two integrations are separate, so configuring one does not configure the other.

Why use SSO

SSO moves Kevel sign-in into the identity system your organization already governs. Signing in through your IdP means:

  • Sign-in is governed by your IdP. Whoever your IdP admits to the Kevel application can sign in, and whoever it does not, cannot.
  • Your authentication policy carries over. Multi-factor authentication and conditional access rules configured in your IdP apply to Kevel sign-ins without being set up again.
  • There is no Kevel-specific password for those users to be issued, rotated, or reset.
  • Sign-in events land in your IdP's logs, alongside every other application your users reach.

Which SSO applies to you?

You are signing in as...You're using...Set up SSO here
A media owner, ad ops or reporting userKevel Ad ServerAd Server SSO
A media owner managing your own networkKevel Ad Server, via Console's "Log in as media owner" linkAd Server SSO
An advertiser or brand using a media owner's self-serve UIKevel ConsoleConsole SSO
📘

Note

If you provide your advertisers a Console instance, you may set up both. Your own users sign in through the Ad Server integration, your advertiser users sign in through the Console integration, and the two meet on your Console sign-in page. See Console sign-in paths.

What each integration supports

CapabilityKevel Ad ServerKevel Console
Who it coversYour media owner usersYour advertiser users
ProtocolSAML 2.0 or OpenID ConnectOpenID Connect
FlowService provider (SP)-initiated onlyService provider (SP)-initiated only
New users created automatically at sign-in (JIT provisioning)Supported (optional)No. An admin invites the advertiser user first
Default access granted automatically to new usersSupported (optional)No. Access is granted per invitation
Access revoked automatically when removed from your IdPNoNo
Access removal from the Kevel sideYes. Deactivate the user in the Kevel UI. Takes effect within about 30 secondsYes. Remove the user's access in Console. Takes effect within about 30 seconds
Email and password sign-in alongside SSONot applicable. SSO replaces the Kevel-native sign-in for your organizationPossible, and best turned off once SSO is working. See the Console page
Roles and permissions via the IdPNo. Set in the Kevel UINo. Set in Console
📘

Authentication, not authorization

Signing in through your IdP confirms who a user is. Authorization (what that user can then see and do) is always set in the corresponding Kevel product, which keeps access decisions with the admins who manage your Kevel account day to day.

Setting up a new SSO integration

Kevel configures both integrations, working from information you provide about your IdP. Review the integration page for the relevant product, and when you're ready, contact your Kevel representative to begin.