Identities and Accounts

Overview

When a user logs into Radancy Hiring Events using SSO, Radancy will automatically provision a user account when one does not exist. This article describes how Radancy provisions user accounts and how Radancy enables you to maintain a relationship between a user's account or identity on your system with the user's Radancy account.

Radancy User Account

Each Radancy user account consists of the following information:

  • id - a numeric identifier that Radancy has assigned to the account
  • first_name - the user's first name
  • last_name - the user's last name
  • email - the user's email address, which also serves as the username on the account
  • time_zone - the user's preferred time zone such as "America/New_York". Radancy uses IANA Olson time zone names.
  • external_id - the unique identifier that identifies the user in your identity management system.

User Accounts and ID Tokens

Radancy supports SSO using OAuth 2.0 and either one of the following identity tokens:

Each of these identity tokens contains information, also called claims, that Radancy uses to create a Radancy account. Let's look at each one.

SAML 2.0

Claims in SAML 2.0 are expressed as attributes. SAML 2.0 uses the object identifier (OID) URN schema defined for X.500 directory systems to define legal values for attribute types. LDAP is a simplified version of X.500 and the most common implementation of this standard. Radancy looks for the following SAML 2.0 attributes when creating a new Radancy account for a user. More information about these attribute types can be found in RFC-4519.

For a complete list of LDAP OIDs, see the LDAP OID Reference or OID Registry.

Friendly Attribute Name OID Attribute Name Required? Definition
userId urn:oid:1.3.6.1.4.1.47993.1.1.2 No the identifier for this user in the external system. Radancy will use the first value it finds in a claim.
mail urn:oid:0.9.2342.19200300.100.1.3 Yes the preferred or primary email address for the user. Radancy will use the first value it finds in a claim.
givenName urn:oid:2.5.4.42 Yes name strings that are the part of a person's name that is not their surname.
surname urn:oid:2.5.4.4 Yes the surname or last name of the user.
ianaTimeZone urn:oid:1.3.6.1.4.1.47993.1.1.3 No the user's preferred time zone such as "America/New_York". Radancy uses IANA Olson time zone names. If one is not provided, the user's time zone is set to "US/Eastern".

If no account exists for the email address in the identity token, then a new account is created using the information above. Radancy will send an email to the email address informing them an account has been created and asking the user to verify their email address.

If an active user account exists for the given email address and the email address has been verified, then Radancy will set the external ID to the subject identifier in the identity token. The account verification email is not sent.

If an active user account exists for the given email address and the email address has not been verified, Radancy will send an email to the user asking them to verify their email address before the account is enabled.

OpenID Connect

When OpenID Connect is used to single sign-on a user into Radancy, Radancy uses the scope request parameter on the authentication request to ensure certain claims are included in the JWT ID token. In addition to the default "openid" scope, Radancy will request the "profile" and "email" scopes. The following table lists the claims that Radancy uses to provision new user accounts and to map external identities to existing Radancy user accounts.

Claim Name Type Required? Definition
sub string Yes the identifier your system uses to identify this user. This claim is always present in OpenID ID Tokens.
given_name string Yes the user's first name or names.
family_name string Yes the surname or last name of the user.
email string Yes the user's preferred email address, which may be the email address they use to log into your applications.
zoneinfo string No the user's time zone. if one is not provided, the user's time zone is set to US/Eastern.

If no account exists for the email address in the identity token, then a new account is created using the information above. If the email address has not be verified, Radancy will send an email to the email address informing them an account has been created and asking the user to verify their email address. If the email address has been verified, the account verification email is not sent.

If an active user account exists for the given email address and the email address has been verified, then Radancy will set the external ID to the subject identifier in the identity token. The account verification email is not sent.

If an active user account exists for the given email address and the email address has not been verified, Radancy will send an email to the user asking them to verify their email address before the account is enabled.

FAQ

Q. Does Radancy support bulk user provisioning?

A. Not at this time. User accounts are provisioned when a user first uses SSO to log into Radancy. Radancy is exploring providing support for SCIM 2.0, which is an open API standard for managing identities that define methods for creating, updating and deleting identities. For more information on SCIM 2.0, see http://www.simplecloud.info/.

Was this article helpful?
0 out of 0 found this helpful