SSO with contractors
How SSO with contractors works in Paycux, what it is for, and the smallest setup that gets it running.
Introduction
SSO with contractors is part of the Paycux platform. This page explains what it does, when to reach for it, and the smallest working setup you can ship.
Everything below applies to both environments. Build and test in staging, then promote the same configuration to production without changing your code — only the API key and client ID differ.
Goals & requirements
Before you start, make sure you have the following in place:
- A Paycux account with access to the project you are configuring.
- An API key for the environment you are working in. Staging keys start with
sk_test_; production keys start withsk_live_. - Admin access on the system you are connecting, so you can create the application and read its metadata.
- A redirect URI registered in the Paycux dashboard under Developer → Redirects.
Integrating SSO
Integrating SSO is handled by SSO with contractors rather than by your application code. Paycux exposes it through the same API surface as the rest of the platform, so the client you already configured needs no additional setup.
Configuration lives in the dashboard and is versioned per environment. Change it in staging, confirm the behaviour, then apply the same change to production.
Enforcing SSO authentication
Every API request is authenticated with a bearer token in the Authorization header. Keys are scoped to a single environment and are shown once at creation — store them in a secret manager, not in source control.
1curl -X GET 'https://api.paycux.com/v1/organizations' \2 -H 'Authorization: Bearer $PAYCUX_API_KEY'
SSO authentication flow
SSO authentication flow applies specifically to SSO with contractors. It behaves the same in both environments, and the values it depends on are visible in the dashboard for the environment you have selected.
If the behaviour you see does not match this description, check which environment your API key belongs to before anything else — a staging key against production data is the most common cause.
Understanding authentication policies
Understanding authentication policies applies specifically to SSO with contractors. It behaves the same in both environments, and the values it depends on are visible in the dashboard for the environment you have selected.
If the behaviour you see does not match this description, check which environment your API key belongs to before anything else — a staging key against production data is the most common cause.
Adding an authentication policy
Adding an authentication policy applies specifically to SSO with contractors. It behaves the same in both environments, and the values it depends on are visible in the dashboard for the environment you have selected.
If the behaviour you see does not match this description, check which environment your API key belongs to before anything else — a staging key against production data is the most common cause.
Summary
Summary is handled by SSO with contractors rather than by your application code. Paycux exposes it through the same API surface as the rest of the platform, so the client you already configured needs no additional setup.
Configuration lives in the dashboard and is versioned per environment. Change it in staging, confirm the behaviour, then apply the same change to production.