Skip to main content

Haste Health Logo

Haste Health Integration

This guide provides step-by-step instructions on integrating a separate Haste Health tenant as an identity provider for your Project.

Prerequisites​

  • Two Haste Health tenants and accounts with access to both tenants' admin apps.

Steps to Integrate Haste Health​

  1. Register a New Application for Haste Health Tenant you wish to use as an Identity Provider

    • Log in to the project's console in the admin app.
    • Open ClientApplication from the sidebar, then click New ClientApplication.
    • Provide the following details:
      • Name: A friendly name for the application (e.g., Haste Health IDP Client).
      • Grant Type: Select Authorization Code
      • Response Types: Select token
      • Scopes: Specify the scopes required for your application (e.g., openid profile email). openid must be allowed here: the client application only issues an id token for scopes it is registered for, and without one the sign-in fails at the callback.
      • Redirect URIs: Add a new redirect URI for your Haste Health tenant that will use this identity provider: https://[haste-health-host]/w/[my-tenant]/system/api/v1/oidc/federated/[idp-resource-id]/callback
  2. Copy Metadata

  3. Configure Haste Health Instance for IDP

    • Open the system console for your tenant where you want to add the identity provider (https://[tenant]--system.[haste-health-host]).
    • Open the Identity providers tab.
    • Click New IdentityProvider.
    • Provide the following details:
      • Name: A friendly name for the identity provider (e.g., Haste Health IDP).
      • Status: Set to active.
      • Access Type: Set to oidc.
      • Authorization_endpoint: The authorization_endpoint copied from step 2.
      • Token_endpoint: The token_endpoint copied from step 2.
      • Jwks_uri: The jwks_uri copied from step 2.
      • Scopes: Specify the scopes required for your application (e.g., openid profile email). openid is always requested even when left out. Add profile and email to populate the new user's name and email address.
      • Client ID: The ClientId copied from step 1.
      • Client Secret: The Client secret copied from step 1.
      • Enable PKCE: We require PKCE so enable this option and use S256 as the code challenge method.
  4. Set Health Tenant redirect URL in Identity Provider Tenant

    • Go back to your Haste Health tenant you are using as an identity provider.
    • Open ClientApplication from the sidebar and click the application you created in step 1.
    • In the "Redirect URIs" section, ensure the redirect URI for your Haste Health tenant that will use this identity provider is added: https://[haste-health-host]/w/[my-tenant]/system/api/v1/oidc/federated/[idp-resource-id]/callback
  5. Test the Integration

    • In the system console, open the Projects tab and click the pencil on the project you want to enable it for.
    • In the project's Form tab, add the Haste Health identity provider under identityProvider, then choose Actions → Update.
    • Click the project and log out.
    • Click to log in using the newly added Haste Health identity provider to ensure everything is set up correctly.