IBM watsonx supports IBM Cloud App ID to integrate customer's registries for user authentication. You configure App ID on IBM Cloud to communicate with an identiry provider. You then provide an alias to the people in your organization to log in
to IBM watsonx.
Required roles
To configure identity providers for App ID, you must have one of the following roles in the IBM Cloud account:
Account owner
Operator or higher on the App ID instance
Operator or Administrator role on the IAM Identity Service
App ID is configured entirely on IBM Cloud. An identity provider, for example, Active Directory, must also be configured separately to communicate with App ID.
Each App ID instance requires a unique alias. There is one alias per account. All users in an account log in with the same alias. When the identity provider is configured, the alias is initially set to the account ID. You can change the initial alias to be easier to type and remember.
Logging in with App ID (beta)
Copy link to section
Users choose App ID (beta) as the login method on the IBM watsonx login page and enter the alias. Then, they are redirected to their company's login page to enter their company credentials. Upon logging in successfully to their
company, they are redirected to IBM watsonx.
To verify that the alias is correctly configured, go to the User profile and settings page. Verify that the username in the profile is the email from your company’s registry. The alias is correct if the correct email is shown
in the profile, as it indicates that the mapping was successful.
You cannot switch accounts when logging in through App ID.
Limitations
Copy link to section
The following limitations apply to this beta release:
You must map the name/username/sub SAML profile properties to the email property in the user registry. If the mapping is absent or incorrect, a default opaque user ID is used, which is not supported in this beta release.
The IBM Cloud login page does not support an App ID alias. Users log in into IBM Cloud with a custom URL, following this form: https://cloud.ibm.com/authorize/{app_id_alias}.
If you are using the Cloud Directory included with App ID as your user registry, you must select Username and password as the option for Manage authentication > Cloud Directory > Settings > Allow users to sign-up and sign-in using.
About cookies on this siteOur websites require some cookies to function properly (required). In addition, other cookies may be used with your consent to analyze site usage, improve the user experience and for advertising.For more information, please review your cookie preferences options. By visiting our website, you agree to our processing of information as described in IBM’sprivacy statement. To provide a smooth navigation, your cookie preferences will be shared across the IBM web domains listed here.