Centralized sign-on
Users authenticate through the SSO portal and can be directed back to approved connected applications after login.
Customizable identity and access management
A centralized Single Sign-On platform for organizations that manage access across multiple internal or external applications.
Product Overview
MySSO OnTime provides a configurable SSO portal that authenticates users, manages identity data, and returns controlled user information to applications that support OAuth2-based login flows.
Users authenticate through the SSO portal and can be directed back to approved connected applications after login.
Administrators can manage users, global platform roles, application-specific roles, account approval, lockout state, and activity information.
Connected applications can receive a tailored JSON response with the profile fields and role assignments agreed for the implementation.
Key Benefits
The offer is designed as a Contact Me engagement. We work with each organization to understand its applications, data needs, roles, and integration path before defining the final scope.
Move participating applications toward a common authentication entry point.
Store approved profile and organizational information in a single administrative platform.
Manage global SSO access separately from the roles each application needs.
Configure organizational levels and user fields around each customer's structure.
Administration
Administrators can maintain the SSO platform and the identity information that participating applications may consume.
OAuth2 Integration
MySSO OnTime is implemented as a .NET web application with OAuth2 support and a relational database backend. Applications redirect users to the SSO, receive the result through an approved callback, and can consume identity data through a controlled JSON response.
The consuming application sends the user to the SSO login flow.
The portal verifies the user and applies configured access rules.
The user is redirected back to the approved application endpoint.
The application receives agreed claims such as user identity, email, organization, applications, and roles.
{
"userId": "USR-10045",
"email": "alex.rivera@example.org",
"fullName": "Alex Rivera",
"employeeId": "EMP-2048",
"organization": {
"division": "Operations",
"directorate": "Digital Services",
"coordinationUnit": "Access Management"
},
"applications": [
{ "name": "Operations Portal", "roles": ["Manager", "Reader"] },
{ "name": "Support Desk", "roles": ["Reviewer"] }
]
}
Customization
The platform can be adjusted to match each organization's role model, profile fields, catalogs, application list, and organizational hierarchy.
Start with divisions, directorates, and coordination units, then add levels, remove levels, or rename structures as needed.
Add, remove, or adjust user fields and JSON claims based on the information the client wants to share with connected applications.
Register applications, callback URLs, and application-specific role assignments for the systems that will consume the SSO.
Define the custom version of the SSO through a discovery meeting and implementation plan instead of a one-size-fits-all SaaS package.
Fit and Scope
Contact Me Process
Share your organization, contact details, and the applications you want to connect.
We discuss login flows, user data, roles, callback needs, and the current application landscape.
The implementation scope is adjusted to the hierarchy, catalogs, fields, and claims the client requires.
The SSO and client applications are aligned around OAuth2 configuration, callback behavior, and user information delivery.
Offer Scope
Out of Scope
Next Step
Use the support form to request more information, describe the applications you want to connect, and start the Contact Me process.