user-lockSSO — End Customers

Enable brand-managed SSO for customer login across Reach-powered web and app experiences.

Overview

End-customer SSO lets customers log in to Reach-powered experiences using brand-managed credentials.

Reach delegates authentication to your Identity Provider (IdP). Reach does not store passwords.

circle-info

Need SSO for Reach Central users? See SSO — Agents.

  • What it is: Brand-managed SSO for customer login.

  • What problem it addresses: Eliminates duplicate accounts and centralizes security policies.

  • Who it is intended for: Customers using Reach-powered web and app experiences.

Typical use cases

  • Let customers reuse an existing brand login.

  • Reduce friction in checkout and self-care.

  • Centralize MFA and security policy under the brand.

Scope

  • What is included:

    • SSO integration for customer login across Reach-powered surfaces:

      • brand website

      • mobile web

      • mobile apps

      • checkout and self-care portals

    • Session creation and identity linkage.

  • What is excluded:

    • Agent SSO for Reach Central

    • Brand password reset and credential management.

    • Customer identity merges or migrations (handled case-by-case).

Brand inputs

  • Which IdP will be used and who owns it.

  • Which identity fields will be used to match customers.

  • A small set of test customers for validation.

  • An approval owner for go-live.

Requesting this bolt-on

For the standard request process, commercial notes, and support, see Bolt-ons catalog.

Technical details

For the implementation-specific setup details, visit: SSO technical detailsarrow-up-right

circle-info

Questions or clarification? Reach out to your respective account manager or email at [email protected]

Last updated