Kingsoft Cloud role-based SSO
Role-based single sign-on (SSO) lets your enterprise users log in to Kingsoft Cloud using their IDaaS accounts, without creating a separate sub-account for each member.
Prerequisites
Before you begin, make sure you have:
-
An active IDaaS instance in the IDaaS console
-
Admin access to both the IDaaS console and the Kingsoft Cloud console
-
The Kingsoft Cloud main account ID (available in the Kingsoft Cloud console under Account and Security)
The identity provider (IdP) name you set in IDaaS (Step 2) must exactly match the IdP name you create in Kingsoft Cloud (Step 3). A mismatch causes SSO to fail.
Step 1: Add the application in IDaaS
-
Log on to the IDaaS console.IDaaS console
-
On the EIAM page, locate your instance and click Manage in the Actions column.

-
In the left-side navigation pane, choose Applications > Add Application.
-
On the Marketplace tab, search for Kingsoft Cloud Role-Based SSO and click Add Application.
-
Confirm the application name and click Add.
Step 2: Configure SSO for the application
After the application is added, you are automatically redirected to the SSO tab.
Step 3: Create an IdP in Kingsoft Cloud
This step establishes the trust relationship between Kingsoft Cloud and IDaaS by uploading the IdP metadata file.
Download the metadata file from IDaaS
In the Application Settings section of the IDaaS application, download the IdP metadata file to your computer. In most cases, the metadata file is in the XML format and contains the logon URLs, the public key for verifying SAML assertions, and the assertion format.
Step 4: Create a role in Kingsoft Cloud
-
Log on to the Kingsoft Cloud console.
-
In the left-side navigation pane, click Roles.
-
On the Roles page, click Create Role.
-
In the Select trusted entity type section, select IdP.
-
In the Set role information section, enter a role name and description.
-
In the Set Carrier information section, select IdP.
-
Click Next.
Step 5: Assign the role to an IDaaS account
-
In the IDaaS console, open the application you added in Step 1.
-
On the Sign-In tab, go to the Application User tab.
-
Select the IDaaS account to use for role-based SSO and add an application account for it. The application account name must match the Kingsoft Cloud role name exactly. To assign multiple Kingsoft Cloud roles to the same IDaaS account, create a separate application account for each role.
Step 6: Test SSO
-
Log on to the IDaaS application portal using the IDaaS account configured in Step 5.
-
Click the Kingsoft Cloud role-based SSO icon to initiate SSO.