Identity Provider Discovery

Pivotal Web Services End of Availability Announced
For more information, see Frequently Asked Questions.

This topic describes Identity Provider (IdP) Discovery and how to configure it for your Pivotal Web Services (PWS) apps that use the Single Sign-On (SSO) service.

What it Does

If users with different email domains access the same PWS app, you can configure SSO to authenticate them through different identity providers.

In this situation, IdP Discovery streamlines the login experience by automatically redirecting the user to their own IdP and shielding them from seeing the IdPs of other app users.

When a user logs in to an app, an account chooser autofills their email address from any previous login, or presents a choice if they have logged in from more than one account. Users can add or remove accounts from the account chooser.


As an example, consider an app used by a company and its competing suppliers and With IdP Discovery, users from all three companies can log in from the same page, and do not have to see or choose from a list of login options that covers all the domains. IdP Discovery ascertains each user’s IdP from their email domain.

Enable IdP Discovery

IdP Discovery is associated with a service plan, and configured for the apps bound to instances of that plan. To enable IdP Discovery for a service plan and the apps that use it, you must be a Plan Administrator.

  1. Enable IdP Discovery for the SSO Service Plan instance that your app is bound to:

    1. Log into the SSO dashboard at using your administrator credentials.
    2. Click the plan name and select Configure under the plan menu.
    3. Select the checkbox under the Identity Provider Discovery section and click Save. Enable IdP Discovery
  2. Click the plan name and select Manage Identity Providers under the plan menu.

  3. Enter the Email domains you want to include as a comma-separated list under the configuration page for the identity provider plan. IdP Discovery Domains

  4. In Apps Manager, navigate to your space, open the Service tab, and select your service instance.

  5. Click the Manage link under the service name, and edit the app configuration by selecting the required Identity Providers.