Customizable identity and access management

MySSO OnTime

A centralized Single Sign-On platform for organizations that manage access across multiple internal or external applications.

  • OAuth2-style login flows
  • Central user and role administration
  • Client-specific identity claims

Product Overview

One identity portal for application ecosystems

MySSO OnTime provides a configurable SSO portal that authenticates users, manages identity data, and returns controlled user information to applications that support OAuth2-based login flows.

Centralized sign-on

Users authenticate through the SSO portal and can be directed back to approved connected applications after login.

User and role control

Administrators can manage users, global platform roles, application-specific roles, account approval, lockout state, and activity information.

Controlled identity response

Connected applications can receive a tailored JSON response with the profile fields and role assignments agreed for the implementation.

Key Benefits

Built for organizations that need a custom-fit SSO layer

The offer is designed as a Contact Me engagement. We work with each organization to understand its applications, data needs, roles, and integration path before defining the final scope.

Reduce repeated login points

Move participating applications toward a common authentication entry point.

Keep identity data consistent

Store approved profile and organizational information in a single administrative platform.

Separate platform and application roles

Manage global SSO access separately from the roles each application needs.

Adapt the hierarchy to the client

Configure organizational levels and user fields around each customer's structure.

Administration

Capabilities for managing access and identity data

Administrators can maintain the SSO platform and the identity information that participating applications may consume.

Admin capabilities

  • Create, approve, lock, unlock, and update users.
  • Store profile details such as name, email, birthdate, gender, employee ID, RFC or tax ID, and profile picture.
  • Register applications that will consume the SSO.
  • Create global SSO roles and application-specific roles.
  • Assign each user to multiple applications with different roles in each application.
  • Review login and activity information.
  • Manage catalogs such as genders and organizational units.
MySSO OnTime
Identity Administration Generic sample view

OAuth2 Integration

A clear login and identity handoff model

MySSO OnTime is implemented as a .NET web application with OAuth2 support and a relational database backend. Applications redirect users to the SSO, receive the result through an approved callback, and can consume identity data through a controlled JSON response.

1

Application redirects

The consuming application sends the user to the SSO login flow.

2

SSO authenticates

The portal verifies the user and applies configured access rules.

3

Callback returns control

The user is redirected back to the approved application endpoint.

4

Identity data is provided

The application receives agreed claims such as user identity, email, organization, applications, and roles.

{
  "userId": "USR-10045",
  "email": "alex.rivera@example.org",
  "fullName": "Alex Rivera",
  "employeeId": "EMP-2048",
  "organization": {
    "division": "Operations",
    "directorate": "Digital Services",
    "coordinationUnit": "Access Management"
  },
  "applications": [
    { "name": "Operations Portal", "roles": ["Manager", "Reader"] },
    { "name": "Support Desk", "roles": ["Reviewer"] }
  ]
}

Customization

Configured around the client's applications and organization

The platform can be adjusted to match each organization's role model, profile fields, catalogs, application list, and organizational hierarchy.

Organizational hierarchy

Start with divisions, directorates, and coordination units, then add levels, remove levels, or rename structures as needed.

Profile fields and claims

Add, remove, or adjust user fields and JSON claims based on the information the client wants to share with connected applications.

Application onboarding

Register applications, callback URLs, and application-specific role assignments for the systems that will consume the SSO.

Deployment scope

Define the custom version of the SSO through a discovery meeting and implementation plan instead of a one-size-fits-all SaaS package.

Fit and Scope

Who it is for, and where the boundary is

Best suited for

  • Organizations with multiple internal or external applications.
  • Teams that need centralized user administration and identity data.
  • Projects where each application can support OAuth2-based login or can be adapted to consume identity data.

Service boundary

  • We provide and customize the SSO platform.
  • The client remains responsible for its existing and future applications.
  • Client applications must integrate with the SSO through OAuth2 or adapt their own local login and user synchronization logic.
  • If a client wants both SSO login and local login, that decision and implementation belongs to the client application.

Contact Me Process

From marketplace interest to implementation scope

01

Request a meeting

Share your organization, contact details, and the applications you want to connect.

02

Review the ecosystem

We discuss login flows, user data, roles, callback needs, and the current application landscape.

03

Define the custom scope

The implementation scope is adjusted to the hierarchy, catalogs, fields, and claims the client requires.

04

Plan integration

The SSO and client applications are aligned around OAuth2 configuration, callback behavior, and user information delivery.

Offer Scope

What is included

  • Customizable SSO portal setup.
  • User, role, application, catalog, and organizational hierarchy management.
  • OAuth2-style integration configuration for approved applications.
  • Configurable UserInfo-style JSON response and identity claims.
  • Discovery and implementation planning for the client's environment.

Out of Scope

What is not included

  • Ownership or maintenance of the client's separate applications.
  • Automatic conversion of applications that do not support OAuth2.
  • Unstated compliance certifications or guarantees.
  • Client-side decisions about maintaining both local login and SSO login.

Next Step

Schedule a conversation about your SSO requirements

Use the support form to request more information, describe the applications you want to connect, and start the Contact Me process.

Contact support