Welcome to the Kinde community.

P
K
A
A
A
Members
Juan Miranda
J
Juan Miranda
Offline, last seen 6 days ago
Joined October 2, 2024

Hi everyone,
At our company, we would like to sign up for the Plus plan to connect with an organization through Entra ID and integrate your product into our website. We don’t have an IT team, so we would be happy to work with you if you can assist us with the implementation.
Our use case might be something you haven’t seen before, and we’ve spoken with you previously. We know that your product meets our needs, but we don’t know how to integrate it into Framer.com.
We would appreciate guidance on how to proceed with the integration and the next steps. My email is juan.miranda@addtimme.com.

1 comment
P

Hello, do you have a guide for integrating your solution into a project on Framer.com?

1 comment
A

Hello everyone!

I have a few questions that I would really appreciate if you could answer as soon as possible:

  1. Is it possible for Kinde to function as a single IdP for my website (built with Framer) and allow SSO via OIDC/OAuth?
  2. Does Kinde allow the discovery of new IdPs registered by organization?
  3. Can each organization connect via SAML/OAuth2/OIDC with the final IdP?

The flow I imagine would look something like this:

Framer ---- Kinde --------------- Org1 IdP
(Identity proxy + discovery)
|--------------------- Org2 IdP
|--------------------- Org3 IdP

Additionally, I am not 100% clear if it is mandatory for the user to be pre-registered in Kinde (my clients), meaning if Just-in-Time Provisioning is supported, which allows user accounts to be created on the fly with the data transmitted by the IdP, both in Kinde and in my final app.

In terms of security, I need to know if the service guarantees that domains from one organization (e.g., Organization A) cannot access Organization B, specifically in the enterprise plan.

Example:

Imagine you have two clients: Amazon and Google.
Amazon users are:

Google users are:


I need a way to limit in the app so that @amazon.com users can only authenticate in Amazon's IdP, and @google.com users can only authenticate in Google's IdP.

Otherwise, it could happen that Google's admin creates user1@amazon.com in their IdP, and in doing so impersonates Amazon's user. Does that make sense?

3 comments
P
D
J