{"componentChunkName":"component---src-templates-acg-portal-new-template-tsx","path":"/1mrfcmm7n","result":{"data":{"markdownRemark":{"html":"<p>本文主要介绍，如何配置外部身份提供商SSO入站</p>\n<h2 id=\"操作说明\"><a href=\"#%E6%93%8D%E4%BD%9C%E8%AF%B4%E6%98%8E\" aria-label=\"操作说明 permalink\" class=\"anchor\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>操作说明</h2>\n<h3 id=\"创建用户池\"><a href=\"#%E5%88%9B%E5%BB%BA%E7%94%A8%E6%88%B7%E6%B1%A0\" aria-label=\"创建用户池 permalink\" class=\"anchor\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>创建用户池</h3>\n<p><strong>操作步骤</strong>：</p>\n<ol>\n<li>Agent Identity控制台-<a href=\"https://console.bce.baidu.com/agentidentity#/user-pool\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">用户池管理</a>，点击「+ 创建用户池」，弹出创建弹窗</li>\n<li>\n<p>填写以下字段：</p>\n<ul>\n<li><strong>用户池名称</strong>（必填）：最多 64 个字符</li>\n<li><strong>描述</strong>（选填）：最多 128 个字符</li>\n</ul>\n</li>\n<li>点击「确定」完成创建</li>\n</ol>\n<p><img src=\"https://rte.weiyun.baidu.com/wiki/attach/image/api/imageDownloadAddress?attachId=4848b03bf0ff4108b6ab6ad9549ad4d7&#x26;docGuid=e7FepzkuhAjnA1\"></p>\n<h3 id=\"创建客户端\"><a href=\"#%E5%88%9B%E5%BB%BA%E5%AE%A2%E6%88%B7%E7%AB%AF\" aria-label=\"创建客户端 permalink\" class=\"anchor\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>创建客户端</h3>\n<p><strong>操作步骤</strong>：</p>\n<ol>\n<li>Agent Identity控制台-用户池管理-<a href=\"https://console.bce.baidu.com/agentidentity#/user-pool/clients\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">客户端</a>，点击「+ 创建客户端」，弹出创建弹窗</li>\n<li>填写以下字段：</li>\n</ol>\n<table>\n<thead>\n<tr>\n<th>字段</th>\n<th>是否必填</th>\n<th>说明</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>客户端名称</td>\n<td>必填</td>\n<td>1-64 位字符</td>\n</tr>\n<tr>\n<td>客户端类型</td>\n<td>-</td>\n<td>当前仅支持「Web 应用」，默认选中</td>\n</tr>\n<tr>\n<td>允许回调 URL</td>\n<td>必填</td>\n<td>用户池中的用户完成登录认证后，页面跳转的目标地址<br/>必须以 https:// 开头，支持添加多个</td>\n</tr>\n</tbody>\n</table>\n<ol start=\"3\">\n<li>点击「确定」完成创建</li>\n</ol>\n<p><img src=\"https://rte.weiyun.baidu.com/wiki/attach/image/api/imageDownloadAddress?attachId=7a8f8e27194140e79b98ec8c1e52e176&#x26;docGuid=sTcB-i8ANjM0cz\"></p>\n<h3 id=\"创建身份提供商\"><a href=\"#%E5%88%9B%E5%BB%BA%E8%BA%AB%E4%BB%BD%E6%8F%90%E4%BE%9B%E5%95%86\" aria-label=\"创建身份提供商 permalink\" class=\"anchor\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>创建身份提供商</h3>\n<p><strong>操作步骤</strong>：</p>\n<ol>\n<li>Agent Identity控制台-用户池管理-<a href=\"https://console.bce.baidu.com/agentidentity#/user-pool/identity-providers\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">外部身份提供商</a>，点击「+ 创建提供商」，右侧滑出创建抽屉面板</li>\n<li>填写表单信息</li>\n</ol>\n<h4 id=\"基本信息\"><a href=\"#%E5%9F%BA%E6%9C%AC%E4%BF%A1%E6%81%AF\" aria-label=\"基本信息 permalink\" class=\"anchor\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>基本信息</h4>\n<table>\n<thead>\n<tr>\n<th>字段</th>\n<th>是否必填</th>\n<th>说明</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>提供商名称</td>\n<td>必填</td>\n<td>最多 64 个字符，该名称会在用户登录页展示供用户选择</td>\n</tr>\n<tr>\n<td>提供商类型</td>\n<td>必填</td>\n<td>选择提供商支持 SSO 协议</td>\n</tr>\n<tr>\n<td>提供商</td>\n<td>必填</td>\n<td>选择自定义配置 或 系统内置的常见身份提供商</td>\n</tr>\n</tbody>\n</table>\n<h4 id=\"oauth-20-协议配置\"><a href=\"#oauth-20-%E5%8D%8F%E8%AE%AE%E9%85%8D%E7%BD%AE\" aria-label=\"oauth 20 协议配置 permalink\" class=\"anchor\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>OAuth 2.0 协议配置</h4>\n<p>根据选择的提供商不同，展示不同的配置表单：</p>\n<p><strong>自定义提供商</strong>：</p>\n<table>\n<thead>\n<tr>\n<th>字段</th>\n<th>是否必填</th>\n<th>说明</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>客户端 ID</td>\n<td>必填</td>\n<td>在外部身份提供商处申请获得的 Client ID</td>\n</tr>\n<tr>\n<td>客户端密钥</td>\n<td>必填</td>\n<td>在外部身份提供商处申请获得的 Client Secret</td>\n</tr>\n<tr>\n<td>授权端点</td>\n<td>必填</td>\n<td>OAuth 2.0协议中的授权端点</td>\n</tr>\n<tr>\n<td>Token 端点</td>\n<td>必填</td>\n<td>OAuth 2.0协议中的Token 端点</td>\n</tr>\n<tr>\n<td>用户信息端点</td>\n<td>必填</td>\n<td>OAuth 2.0协议中的用户信息端点</td>\n</tr>\n<tr>\n<td>Scope 授权范围</td>\n<td>选填</td>\n<td>根据提供商要求，配置Scope 授权范围</td>\n</tr>\n</tbody>\n</table>\n<p><strong>钉钉提供商</strong>：</p>\n<table>\n<thead>\n<tr>\n<th>字段</th>\n<th>是否必填</th>\n<th>说明</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>客户端 ID</td>\n<td>必填</td>\n<td>钉钉开放平台应用的 AppKey</td>\n</tr>\n<tr>\n<td>客户端密钥</td>\n<td>必填</td>\n<td>钉钉开放平台应用的 AppSecret</td>\n</tr>\n<tr>\n<td>Scope 授权范围</td>\n<td>必填</td>\n<td>默认包含 openid（不可移除）和 corpid（可移除），可追加自定义 scope<br/>建议此处不做改动</td>\n</tr>\n</tbody>\n</table>\n<h4 id=\"用户映射\"><a href=\"#%E7%94%A8%E6%88%B7%E6%98%A0%E5%B0%84\" aria-label=\"用户映射 permalink\" class=\"anchor\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>用户映射</h4>\n<table>\n<thead>\n<tr>\n<th>字段</th>\n<th>是否必填</th>\n<th>说明</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>自动创建用户</td>\n<td>-</td>\n<td>开关控制，默认关闭。开启后，使用身份提供商登录时若平台内不存在映射用户，将自动创建</td>\n</tr>\n<tr>\n<td>用户唯一标识 → username</td>\n<td>必填</td>\n<td>配置身份提供商返回的用户信息中，用于映射 Agent Identity 用户名的字段。钉钉预置为 <code>unionId</code><br/><strong>此字段十分关键，用于单点登录时的用户映射，即单点登录到用户池中的哪个用户</strong></td>\n</tr>\n<tr>\n<td>显示名映射字段 → displayname</td>\n<td>选填</td>\n<td>开启「自动创建用户」后可见。钉钉预置为 <code>nick</code><br/><strong>自动创建用户时，取身份提供商返回的哪个字段作为用户的显示名，非必填</strong></td>\n</tr>\n</tbody>\n</table>\n<ol start=\"3\">\n<li>点击「确定」完成创建</li>\n</ol>\n<p><strong>说明</strong>：</p>\n<ul>\n<li>创建成功后，身份提供商默认处于「启用」状态</li>\n<li>创建成功后，用户登录页会自动展示该身份提供商登录选项</li>\n</ul>\n<p><img src=\"https://rte.weiyun.baidu.com/wiki/attach/image/api/imageDownloadAddress?attachId=b0f0d252faa44c3bbfee6a9cf11fb5bd&#x26;docGuid=eRdmFm-cS2vpR2\"></p>\n<h3 id=\"用户登录\"><a href=\"#%E7%94%A8%E6%88%B7%E7%99%BB%E5%BD%95\" aria-label=\"用户登录 permalink\" class=\"anchor\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>用户登录</h3>\n<p><strong>操作步骤</strong>：</p>\n<ol>\n<li>查看上述创建的客户端详情，复制登录页面 URL</li>\n</ol>\n<p><img src=\"https://rte.weiyun.baidu.com/wiki/attach/image/api/imageDownloadAddress?attachId=158adeaad2df4ac9ba0519bee908a8c2&#x26;docGuid=5wE4MWDM5qwKSF\"></p>\n<ol start=\"2\">\n<li>用户访问登录页面 URL，使用配置的外部身份提供商登录</li>\n</ol>\n<p><img src=\"https://rte.weiyun.baidu.com/wiki/attach/image/api/imageDownloadAddress?attachId=095bd52f17df491bafe97d073f59fe77&#x26;docGuid=ZZcaGXinxKm4hx\"></p>","fields":{"slug":"1mrfcmm7n","title":"外部身份提供商SSO入站","date":"2026-07-13","extractedHeadings":[]},"headings":[{"value":"操作说明","depth":2},{"value":"创建用户池","depth":3},{"value":"创建客户端","depth":3},{"value":"创建身份提供商","depth":3},{"value":"基本信息","depth":4},{"value":"OAuth 2.0 协议配置","depth":4},{"value":"用户映射","depth":4},{"value":"用户登录","depth":3}]}},"pageContext":{"isCreatedByStatefulCreatePages":false,"slug":"1mrfcmm7n","prev":{"id":"Jmrfcjepc","name":"用户名密码登录入站","path":"Jmrfcjepc","filePath":"入站/用户名密码登录入站.md","seo":null,"parentIds":["Mmra9qdxq"],"parents":[{"id":"Mmra9qdxq","documentId":"b59f3b97-4320-4203-ac50-9a679442cec0","name":"入站","repoName":"AGENT_ID","filePath":"入站","disabled":false,"path":"Mmra9qdxq","lastMergeTime":null,"isApiDoc":null,"httpMethod":null,"seo":null,"sourceOrgName":null,"sourceRepoName":null,"sourceDocumentId":""}]},"next":{"id":"umrfcpzi6","name":"出站","path":"umrfcpzi6","filePath":"出站/出站概述.md","seo":null,"parentIds":["wmrfbb8pm"],"parents":[{"id":"wmrfbb8pm","documentId":"66bed742-6b8f-41d0-9be0-6efbd48a6010","name":"出站","repoName":"AGENT_ID","filePath":"出站","disabled":false,"path":"wmrfbb8pm","lastMergeTime":null,"isApiDoc":null,"httpMethod":null,"seo":null,"sourceOrgName":null,"sourceRepoName":null,"sourceDocumentId":""}]},"parents":[{"id":"Mmra9qdxq","documentId":"b59f3b97-4320-4203-ac50-9a679442cec0","name":"入站","repoName":"AGENT_ID","filePath":"入站","disabled":false,"path":"Mmra9qdxq","lastMergeTime":null,"isApiDoc":null,"httpMethod":null,"seo":null,"sourceOrgName":null,"sourceRepoName":null,"sourceDocumentId":""}],"specificSeo":null}}}