Identity Providers

Identity providers in Keyfactor Command control how users authenticate to the Keyfactor Command Management Portal and the Keyfactor APIClosed An API is a set of functions to allow creation of applications. Keyfactor offers the Keyfactor API, which allows third-party software to integrate with the advanced certificate enrollment and management features of Keyfactor Command..

During installation, you select an identity provider type (Active Directory or OAuth). For OAuth configurations, one or more identity providers may be configured. In most environments, this configuration does not need to change after installation.

If you need to migrate from one identity provider type to another, or add additional OAuth identity providers, you can do so by re-running the Keyfactor Command configuration wizard, using the Management Portal, or through the Keyfactor API.

Authentication with only one identity provider type at a time (Active Directory or OAuth) is supported per Keyfactor Command server. Existing identity providers can be modified, but they cannot be deleted.

Tip:  Where to find this in the Management Portal:
System Settings → Identity Providers
Tip:  Click the help icon () next to the Identity Providers page title to open the Keyfactor Software & Documentation Portal to this section. You will receive a prompt indicating:

You are being redirected to an external website ‘software.keyfactor.com'. Would you like to proceed?

You can also find Help in the NavigatorClosed The Navigator is the Keyfactor Command left-hand (newer versions) or top (older versions) navigation menu. Certificate collections and reports can be configured to be added to the menu using user-defined Show in Navigator settings.. From here you can choose to open either the Keyfactor Software & Documentation Portal at the home page or the Keyfactor API Endpoint Utility.

Keyfactor provides two sets of documentation: the On-Premises Documentation Suite and the Managed Services Documentation Suite. Which documentation set is accessed is determined by the Application Settings: On-Prem Documentation setting (see Application Settings: Console Tab).