Single Sign-On
Choose between Ad Server SSO for your media owner users and Console SSO for your advertiser users.
Kevel has two SSO integrations, and which one applies depends on who is signing in: your own users, or the advertisers using your Console instance.
- Ad Server SSO is for your media owner users. It covers every way they sign in, both directly to the Kevel Ad Server and through the "Log in as media owner" link on your Console sign-in page.
- Console SSO is for your advertiser users. It signs them in to your Console instance through your identity provider, instead of a Console password.
Both authenticate against your identity provider (IdP). The two integrations are separate, so configuring one does not configure the other.
Why use SSO
SSO moves Kevel sign-in into the identity system your organization already governs. Signing in through your IdP means:
- Sign-in is governed by your IdP. Whoever your IdP admits to the Kevel application can sign in, and whoever it does not, cannot.
- Your authentication policy carries over. Multi-factor authentication and conditional access rules configured in your IdP apply to Kevel sign-ins without being set up again.
- There is no Kevel-specific password for those users to be issued, rotated, or reset.
- Sign-in events land in your IdP's logs, alongside every other application your users reach.
Which SSO applies to you?
| You are signing in as... | You're using... | Set up SSO here |
|---|---|---|
| A media owner, ad ops or reporting user | Kevel Ad Server | Ad Server SSO |
| A media owner managing your own network | Kevel Ad Server, via Console's "Log in as media owner" link | Ad Server SSO |
| An advertiser or brand using a media owner's self-serve UI | Kevel Console | Console SSO |
NoteIf you provide your advertisers a Console instance, you may set up both. Your own users sign in through the Ad Server integration, your advertiser users sign in through the Console integration, and the two meet on your Console sign-in page. See Console sign-in paths.
What each integration supports
| Capability | Kevel Ad Server | Kevel Console |
|---|---|---|
| Who it covers | Your media owner users | Your advertiser users |
| Protocol | SAML 2.0 or OpenID Connect | OpenID Connect |
| Flow | Service provider (SP)-initiated only | Service provider (SP)-initiated only |
| New users created automatically at sign-in (JIT provisioning) | Supported (optional) | No. An admin invites the advertiser user first |
| Default access granted automatically to new users | Supported (optional) | No. Access is granted per invitation |
| Access revoked automatically when removed from your IdP | No | No |
| Access removal from the Kevel side | Yes. Deactivate the user in the Kevel UI. Takes effect within about 30 seconds | Yes. Remove the user's access in Console. Takes effect within about 30 seconds |
| Email and password sign-in alongside SSO | Not applicable. SSO replaces the Kevel-native sign-in for your organization | Possible, and best turned off once SSO is working. See the Console page |
| Roles and permissions via the IdP | No. Set in the Kevel UI | No. Set in Console |
Authentication, not authorizationSigning in through your IdP confirms who a user is. Authorization (what that user can then see and do) is always set in the corresponding Kevel product, which keeps access decisions with the admins who manage your Kevel account day to day.
Setting up a new SSO integration
Kevel configures both integrations, working from information you provide about your IdP. Review the integration page for the relevant product, and when you're ready, contact your Kevel representative to begin.
Updated 3 days ago
