Яндекс.Метрика
SSO in Pachca with Keycloak

SSO in Pachca with Keycloak

The Pachca integration uses the OpenID Connect protocol.

Go to the Realm you'll use for the Pachca integration. It must not be the Master realm.

Create a new Client and send us its name.

alt

Under Valid redirect URIs, add:

  • msauth.co.staply.pachca://auth
  • com.pachca.app://oidc
  • Your unique URL, which we'll send you

alt

Client authentication must be turned on.

In Credentials, copy the Secret and send it to us.

Automatic logout from Pachca (Backchannel logout)

You can set up automatic session termination: when an employee logs out of their account in the SSO provider, their Pachca session ends too.

To do this, open the client you created for Pachca in Keycloak and, under Logout settings:

  1. Turn off Front channel logout.
  2. In the Backchannel logout URL field, enter https://auth.pachca.com/realms/<your realm name>/protocol/openid-connect/logout/backchannel-logout. Pachca support will give you the exact URL.
  3. Turn on Backchannel logout session required.
  4. Turn on Backchannel logout revoke offline sessions.

Once you're done, contact Pachca support, and we'll turn on Backchannel logout on our side.

Sync employee attributes to Pachca

To illustrate, we'll walk through passing an attribute from Windows ADFS to Pachca via Keycloak.

First, set up attribute passing to Keycloak.

In AD FS Management, open the settings of the application you created for Pachca.

alt

Click "Edit…" 👇

alt

On the "Issuance Transform Rules" tab, click "Edit Rule…"

Fill in the table with the attributes you need.

alt

For example, to pass an employee's groups, select the "Is-Member-Of-DL" field.

In Keycloak, go to the settings of the client you created for Pachca under "Clients".

alt

Go to "Client scopes"

Click the first item in the list, "<client name>-dedicated".

Click "Configure a new mapper".

alt

Select "User Attribute" from the list 👇

alt

Fill in the form with the required values. In this example, we pass the value of the "groupTags" attribute to Pachca.

For the integration between Pachca tags and Active Directory groups to work, the attribute must have this exact name.

alt

And here's how to pass an employee's phone number to Pachca:

alt

🎉 That's it. The next time an employee logs in with SSO, their new attribute values will be passed to Pachca.

To add other fields to an employee's Pachca profile, specify the attribute name in the mapping:

  • Phone: phone_number
  • Job title: title
  • Department: department
  • Group tags: group_tags

You can also pass any other text fields from your directory to Pachca, like an employee's manager or birthday. To do this:

  1. Create the field in Members in the Pachca interface (Members -> settings -> add field -> set a name and any type except "File")
  2. Specify the attribute name in the mapping, as described above for the standard profile fields

Once you've set up the mapping, let our support team know so we can connect it

Updated: February 17, 2025

More in Administration

Accounts in Pachca
How Pachca is structured: the difference between an account, a user and a member profile
Inviting your team
How to invite your team to Pachca, the team chat app: two ways to add employees
Change your email in Pachca
How to change your email address in Pachca: a guide for employees and administrators
Errors when adding people by email
Common errors when adding users to Pachca by email and how to fix them
Managing members in Pachca
Managing members in Pachca: how to add, edit and remove people from your team
Group tags
Add employees to all the chats they need at once with group tags
Advanced administration via API
How to automate user administration in Pachca with the API: creating users, managing them and tags
Ports and addresses Pachca needs
Ports and addresses Pachca needs to work properly: setting up your corporate firewall
Storage in Pachca
Everything about file storage in Pachca: limits, managing storage space and working with documents
Setting up DLP in Pachca
Add an extra layer of protection for personal data, tokens and passwords
Internal/external file access
How to set up internal and external zones in Pachca to protect your company documents
Two-factor authentication (2FA)
How to turn on two-factor authentication in Pachca for extra account security
Import chats from Slack
How to import your chat history from Slack into Pachca: a step-by-step migration guide
Import chats from Mattermost
Pachca lets you move your chat history and files from Mattermost into your workspace.
Import chats from Telegram
If your team is moving to Pachca from Telegram, you can bring your chat history over to your team chat app.
Exporting messages from Pachca
How to export messages from Pachca: data format, settings and export limitations
SSO options in Pachca
Single sign-on (SSO) in Pachca: SAML, LDAP and Keycloak connection options and step-by-step guides
SSO in Pachca with LDAP
SSO in Pachca with Multifactor.ru
SSO in Pachca with Blitz Identity Provider
SSO in Pachca with Authentik
SSO in Pachca with Azure OpenID
SSO in Pachca with ADFS OpenID
This guide explains how to configure ADFS on Windows Server 2016 or later to connect it to Pachca.
SSO in Pachca with Google Workspace SAML
SSO in Pachca with Indeed IdP over SAML
SSO in Pachca with Yandex 360
SSO in Pachca with Yandex Identity Hub
BYOK: Bring Your Own Key in Pachca
How encryption with your own key (BYOK) works in the Pachca team chat app
Advanced encryption in Pachca
How to set up advanced encryption in Pachca for extra protection of your company data
Set up BYOK with HashiCorp Vault
Set up BYOK with Yandex KMS
Set up BYOK with Cloud.ru KMS