Connect Hextal to your identity provider via Keycloak and OIDC. Single sign-on for all your tools.
Hextal integrates natively with Keycloak, the most widely deployed open-source identity and access manager in enterprises, via the standard OpenID Connect (OIDC) protocol. This integration allows your employees to log into Hextal with the same credentials as their other enterprise tools — Active Directory, Google Workspace, LinkedIn, or any other OIDC/SAML provider.
SSO (Single Sign-On) eliminates login friction: the user authenticates once in the morning on their workstation and accesses Hextal without re-entering a password. This simplicity improves platform adoption and reduces security risks linked to password multiplication. When an employee leaves, deactivating their account in Keycloak instantly revokes all their access.
Beyond SSO, Keycloak manages roles and permissions: you can map your Active Directory groups or internal roles to Hextal roles (administrator, manager, employee, external guest). The integration also supports Just-In-Time provisioning: a new user created in Keycloak is automatically provisioned in Hextal on first login.
Your employees use their usual credentials. No need to manage yet another account and password.
Create a user in your Active Directory: they are automatically available in Hextal on first login.
Disable an account in Keycloak = all Hextal access is cut. Secure offboarding in one action.
OIDC, SAML, LDAP — standard protocols are supported. Compatible with Azure AD, Okta, Google Workspace, etc.