KIOWARE CONNECTOR BLUEPRINT

OIDC and SAML Integration

Connect Kiosks to IdPs, SSO, session binding, logout and step-up authentication.

API · TRUST · EVIDENCE

Governed integration pattern

Contract

OpenAPI, schemas, errors, idempotency and versioning.

Trust

Identity, mTLS, tokens, policy and masking.

Evidence

Tracing, audit, reconciliation and acceptance evidence.

INTEGRATION DISCOVERY

Discovery checklist

  • Source and target systems and owners
  • Inputs, outputs and data classification
  • Authentication, trust boundaries and network
  • Timeout, retry, idempotency and reconciliation
  • PoC dataset, UAT evidence and rollback
REFERENCE WORKFLOW

Reference identity flow

01

Session initiation

The Kiosk creates state, nonce and a correlation ID before redirecting the user to the IdP.

02

Authentication and consent

The IdP authenticates the user; attribute scope and step-up rules are defined by project policy.

03

Session binding

KioWare binds subject, device and transaction session; tokens must not be logged or stored long-term on the Kiosk.

04

Secure termination

Logout, timeout and revocation are tested for success, cancellation and connectivity-loss paths.

SECURITY & ACCEPTANCE

Controls before implementation

  • Issuer, audience, redirect URI and signing algorithms must be allowlisted.
  • Clock skew, token lifetime and refresh strategy must be agreed during security review.
  • SAML assertion or OIDC claim mapping needs an owner and version control.
  • UAT evidence should cover login, step-up, logout, timeout and recovery.
Book a Technical Workshop

Confirm contracts, trust boundaries, test data and UAT criteria with the architecture team.

Book a Technical Workshop
EXECUTIVE BRIEFING · TECHNICAL WORKSHOP

Turn a Kiosk requirement into an auditable delivery scope

Assess TCO, APIs, HAL, IAM, peripherals, PoC, UAT and the production roadmap with the KioWare team.