> For the complete documentation index, see [llms.txt](https://atd-dts.gitbook.io/moped-documentation/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://atd-dts.gitbook.io/moped-documentation/dev-guides/authentication/single-sign-on-with-ctm.md).

# Single Sign-On with ATS

Initially, Michael Shanks created the Active Directory application in Azure for us. I found Active directory to be completely empty, so I had to make some initial adjustments for the two environments (production and staging). If you need access to the application settings, please feel free to reach out to him and ask him for ownership permission.

### Certificate renewal (every 3 years)

Every 3 years, we'll received a notification that our SSO certificates need to be renewed/updated. The email will contain instructions that differ slightly from what the UI is currently showing. Here are the [latest steps with updates from the renewals on 8/11/2026 (staging) and 8/12/2026 (production)](https://github.com/cityofaustin/atd-data-tech/issues/29516).

1. In the Azure portal ([staging](https://portal.azure.com/#view/Microsoft_AAD_IAM/ManagedAppMenuBlade/~/SignOn/objectId/6c5f8303-a03b-4855-8822-fbd1d8e8367f/appId/8ab9e10b-e6c9-42f4-996b-ddd9d0d5def8) first to test and then follow same steps for [production](https://portal.azure.com/#view/Microsoft_AAD_IAM/ManagedAppMenuBlade/~/SignOn/objectId/6c5f8303-a03b-4855-8822-fbd1d8e8367f/appId/8ab9e10b-e6c9-42f4-996b-ddd9d0d5def8)), go to the Single sign-on page for the environment.
2. If you do not have access to these pages, you will need to request to become to have the **Owner** role from another owner on DTS (John Clary, Mike Dilley, or Frank Hereford - owners can add other owners) or request access from ATS.
3. In the SAML Signing Certificate section, click Edit in the "Token signing certificate" area to open a new menu that shows existing active and expired certificates. Then, click "+ New certificate".
4. The certificate expiration will default to 3 years which is the maximum. You might need to click around other menus in the form to make the "Save" button active. Save.
5. You will now see a new certificate that is marked as "Inactive". Open the menu in the row of the new certificate and select "Make new certificate active". Click Save at the top. This will roll over your existing certificate to the newly created certificate.
6. Download the federated new certificate XML which contains the new value for the X509 tag in the XML so you can check for it in the next step.
7. Check the [staging (dev) metadata endpoint](https://login.microsoftonline.com/5c5e19f6-a6ab-4b45-b1d0-be4608a9a67f/federationmetadata/2007-06/federationmetadata.xml?appid=85f11cae-9763-4338-a494-e1d4a8beea0e) or the [production metadata endpoint](https://login.microsoftonline.com/5c5e19f6-a6ab-4b45-b1d0-be4608a9a67f/federationmetadata/2007-06/federationmetadata.xml?appid=8ab9e10b-e6c9-42f4-996b-ddd9d0d5def8) to make sure that the new value propagated.

### Important Links

#### Production Setting Links

Name: ATD - Mobility Project Database - Production

Enterprise application management:

[Entra Enterprise Application Settings](https://entra.microsoft.com/#view/Microsoft_AAD_IAM/ManagedAppMenuBlade/~/Overview/objectId/6c5f8303-a03b-4855-8822-fbd1d8e8367f/appId/8ab9e10b-e6c9-42f4-996b-ddd9d0d5def8/preferredSingleSignOnMode/saml/servicePrincipalType/Application/fromNav/)

Outdated Azure AD Application settings link:

<https://aad.portal.azure.com/#blade/Microsoft\\_AAD\\_IAM/ManagedAppMenuBlade/SignOn/objectId/6c5f8303-a03b-4855-8822-fbd1d8e8367f> /appId/8ab9e10b-e6c9-42f4-996b-ddd9d0d5def8/menuItemId/Overview\
Note: Under the “overview” you’ll have to select “Single sign-on” to see SSO configurations.

App Federation URL:

<https://login.microsoftonline.com/5c5e19f6-a6ab-4b45-b1d0-be4608a9a67f/federationmetadata/2007-06/federationmetadata.xml>? appid=8ab9e10b-e6c9-42f4-996b-ddd9d0d5def8

Login Url:

<https://login.microsoftonline.com/5c5e19f6-a6ab-4b45-b1d0-be4608a9a67f/saml2>

Azure AD Identifier:

<https://sts.windows.net/5c5e19f6-a6ab-4b45-b1d0-be4608a9a67f/>

#### Staging Setting Links

Name: ATD - Mobility Project Database - Dev

Enterprise application management:

[Entra Enterprise Application settings](https://entra.microsoft.com/#view/Microsoft_AAD_IAM/ManagedAppMenuBlade/~/Overview/objectId/d9d0e209-4d36-4cae-bd70-99112879e228/appId/85f11cae-9763-4338-a494-e1d4a8beea0e/preferredSingleSignOnMode/saml/servicePrincipalType/Application/fromNav/)

Outdated Azure AD Application settings link:

<https://aad.portal.azure.com/#blade/Microsoft\\_AAD\\_IAM/ManagedAppMenuBlade/Overview/appId/85f11cae-9763-4338-a494-e1d4a8beea0e> /objectId/d9d0e209-4d36-4cae-bd70-99112879e228\
Note: Under the “overview” you’ll have to select “Single sign-on” to see SSO configurations.

App Federation URL:

<https://login.microsoftonline.com/5c5e19f6-a6ab-4b45-b1d0-be4608a9a67f/federationmetadata/2007-06/federationmetadata.xml>? appid=85f11cae-9763-4338-a494-e1d4a8beea0e

Login Url:

<https://login.microsoftonline.com/5c5e19f6-a6ab-4b45-b1d0-be4608a9a67f/saml2>

Azure AD Identifier:

<https://sts.windows.net/5c5e19f6-a6ab-4b45-b1d0-be4608a9a67f/>

#### Other Resourceful Links

IDP Authentication - AWS/SAML-specific: <https://docs.aws.amazon.com/cognito/latest/developerguide/cognito-user-pools-saml-idp.html>

<https://docs.aws.amazon.com/cognito/latest/developerguide/cognito-user-pools-saml-idp-authentication.html>

<https://d1.awsstatic.com/whitepapers/architecture/AWS_Well-Architected_Framework.pdf>

<https://docs.amplify.aws/lib/auth/getting-started/q/platform/js/>

### Set up in AWS

Whenever inside of Cognito, you can go to the **Identity providers** section where you will see the **SAML** option enabled. Within the SAML settings, you will see the metadata URL that links Cognito to AzureAD. You may be able to edit the existing active provider as shown below as ctm-azure-ad by clicking in the pencil icon. That simply configures Cognito to reach out to CTM's AzureAD's user base.&#x20;

![](https://1420082453-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MIQvl_rKnZ_-wHRdp4J%2Fuploads%2FgZweLxjAg2OkuHFluj14%2Fimage.png?alt=media\&token=45bcb35d-ad9c-4b7c-88f6-70b6b360932e)

Within azure AD you would simply provide AWS's federation link.

![](https://1420082453-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MIQvl_rKnZ_-wHRdp4J%2Fuploads%2F0W1z7uFlptfXnHG3pbN8%2Fimage.png?alt=media\&token=06076070-fca1-4f01-87ed-e2203abe62a2)

We need to have at least two things:

The identifier (Entity ID)

The Reply URL (Assertion Consumer Service URL)

The Identifier (Entity ID) To begin with, we must must copy the Cognito Pool ID, and paste it in this format:

`urn:amazon:cognito:sp:`&#x20;

For production, the identifier looks like this:

`urn:amazon:cognito:sp:us-east-1_Zc3pNWX51`

The Reply URL The reply URL comes in this format:

`https://.auth..amazoncognito.com/saml2/idresponse`

In our case, it looks like this for production:

`https://atd-moped-production.auth.us-east-1.amazoncognito.com/saml2/idresponse`

Once you save the settings, it looks like this in production:

![](https://1420082453-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MIQvl_rKnZ_-wHRdp4J%2Fuploads%2FxQGAn4FvgS6WAwChhriU%2Fimage.png?alt=media\&token=d6e65bff-f3f5-4b7e-b5c5-d7ec4164bc38)

This should be enough to get started, AWS is linked to AzureAD and AzureAD is linked to Cognito.

#### Testing your settings

At first you may use cognito's UI, no need to implement javascript. To do so, you need these specific links:

Using your own links for production, you can use these links:

#### For access-token login:

https\://\<COGNITO URL>/login?response\_type=token\&client\_id=\&redirect\_uri=

**For a code-based login (preferred):**

https\://\<COGNITO URL>/login?response\_type=code\&client\_id=\&redirect\_uri=&#x20;

#### Production example access token login:

The last two links only show the patterns, to make use of them you can try this:

<https://atd-moped-production.auth.us-east-1.amazoncognito.com/login?response\\_type=token\\&client\\_id=ins01e2a8d3vd8apvnd0jv10c\\&redirect\\_uri=https://mobility.austin.gov/moped/session/signin>

#### Production example code login (preferred):

<https://atd-moped-production.auth.us-east-1.amazoncognito.com/login?response\\_type=code\\&client\\_id=ins01e2a8d3vd8apvnd0jv10c\\&redirect\\_uri=https://mobility.austin.gov/moped/session/signin>

#### For staging:

<https://atd-moped-staging.auth.us-east-1.amazoncognito.com/login?response\\_type=token\\&client\\_id=3u9n9373e37v603tbp25gs5fdc\\&redirect\\_uri=https://moped.austinmobility.io/moped/session/signin>

<https://atd-moped-staging.auth.us-east-1.amazoncognito.com/login?response\\_type=code\\&client\\_id=3u9n9373e37v603tbp25gs5fdc\\&redirect\\_uri=https://moped.austinmobility.io/moped/session/signin>

#### Redirect URI Warning

For SSO, the redirect URI needs to be listed in the allowed urls list in cognito (App client page).&#x20;

![](https://1420082453-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MIQvl_rKnZ_-wHRdp4J%2Fuploads%2FOq9zlHMdjX1PsnUapzJY%2Fimage.png?alt=media\&token=fe2842d7-3dab-47f7-9dd2-39951287beec)

### Final Notes

This should cover the general overview on how to set up SSO with SAML in AWS Cognito. For additional instructions on how exactly the JavaScript internals work, visit the code base and AWS Amplify documentation:

<https://docs.amplify.aws/lib/auth/getting-started/q/platform/js/>
