Overview
The FUYL Smart Locker System can be configured to offer authentication via Single Sign-On (SSO), allowing users to access the system using their existing credentials via a familiar interface.
If configured, users can also authenticate via QR Code or URL with confirmation code on their own devices, while still using SSO behind the scenes.
Administrators are always given the option to authenticate with SSO or a QR Code, regardless of authentication methods configured for users.
It is recommended to comprehensively Plan your Identity and Authentication before implementing any changes.
Supported Authentication Methods
- Kiosk-based SSO (direct authentication on the FUYL Kiosk)
- QR Code authentication (scan with personal device)
- URL with confirmation code (access via personal device)
The term "SSO" encompasses both direct kiosk authentication and delegated authentication via QR Code/URL methods.
Benefits and Limitations
Enhanced security: SSO authentication inherits organizational security policies and can include multi-factor authentication (MFA).
Convenience trade-off: While more secure, SSO requires that users remember and enter their full credentials, which may not be as fast as simpler methods like Login ID or RFID.
Using SSO Authentication
When a user initiates a workflow at the FUYL Kiosk, authentication options are presented based on configuration.
SSO: The user is redirected to the Identity Provider's authentication screen directly on the kiosk (e.g., Google Workspace, Microsoft Entra).
QR Code: The kiosk displays a QR code and URL with confirmation code. Using a personal device, the user scans the QR code or visits the URL, then authenticates through the organisation's IdP. They may also opt to Sign In Manually should they prefer.
Enabling SSO Authentication
Setting up SSO requires administrative configuration For detailed setup instructions and supported Identity Providers, see Set up SSO & Provisioning.
Process
- In the FUYL.io Portal, navigate to Settings -> FUYL Kiosk Login
- Select either SSO or QR Code
- Save
Additional Customisation
As authentication is handled by the organisation's Identity Provider (IdP), any interface customisation such as logos or branding can be configured directly within the IdP's own settings.