You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: en/on-call/integration/webhooks/alert-webhook.mdx
+8Lines changed: 8 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -234,5 +234,13 @@ Click **View Details** on a record to see the complete request and response info
234
234
- Services can filter based on event_time; if a later event has been received, earlier events can be filtered out. Each push carries the latest complete information, so occasional event loss is tolerable
235
235
236
236
4.**Trusted IP whitelist for push source?**
237
+
{/* console:
237
238
- {ip_whitelist}
238
239
- May be updated in the future, please check regularly
240
+
*/}
241
+
<divclassName="hide">
242
+
243
+
-`47.94.95.118`, `123.56.8.183`, `47.94.193.81`, and `1.13.19.96` (SaaS only; in a private deployment, pushes originate from your own environment's egress address — check with your infrastructure team)
244
+
- May be updated in the future, please check regularly
Copy file name to clipboardExpand all lines: en/on-call/integration/webhooks/custom-actions.mdx
+8Lines changed: 8 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -333,5 +333,13 @@ When an incident is confirmed to impact production services, trigger external st
333
333
- eof
334
334
335
335
3.**Trusted IP whitelist for push source?**
336
+
{/* console:
336
337
- {ip_whitelist}
337
338
- May be updated in the future, please check regularly
339
+
*/}
340
+
<divclassName="hide">
341
+
342
+
-`47.94.95.118`, `123.56.8.183`, `47.94.193.81`, and `1.13.19.96` (SaaS only; in a private deployment, pushes originate from your own environment's egress address — check with your infrastructure team)
343
+
- May be updated in the future, please check regularly
Copy file name to clipboardExpand all lines: en/on-call/integration/webhooks/incident-webhook.mdx
+8Lines changed: 8 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -350,5 +350,13 @@ Click **View Details** on a record to see the complete request and response info
350
350
- Services can filter based on event_time; if a later event has been received, earlier events can be filtered out. Each push carries the latest complete information, so occasional event loss is tolerable
351
351
352
352
4.**Trusted IP whitelist for push source?**
353
+
{/* console:
353
354
- {ip_whitelist}
354
355
- May be updated in the future, please check regularly
356
+
*/}
357
+
<divclassName="hide">
358
+
359
+
-`47.94.95.118`, `123.56.8.183`, `47.94.193.81`, and `1.13.19.96` (SaaS only; in a private deployment, pushes originate from your own environment's egress address — check with your infrastructure team)
360
+
- May be updated in the future, please check regularly
Copy file name to clipboardExpand all lines: en/platform/configure-sso.mdx
+22Lines changed: 22 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -5,6 +5,28 @@ description: Sign in once and access multiple connected applications through sin
5
5
6
6
Flashduty supports Single Sign-On (SSO) via SAML2.0, OIDC, CAS, and LDAP (private deployment only) protocols, helping you easily integrate with various applications and platforms. Users only need to sign in once to access multiple connected applications and services without repeated authentication.
7
7
8
+
## Network Access Requirements
9
+
10
+
---
11
+
12
+
Each protocol has different network reachability requirements for your identity provider (IdP). Confirm this before configuring to avoid sign-in failures caused by network access:
13
+
14
+
| Protocol | Does Flashduty need to reach the IdP? | Details |
15
+
| --- | --- | --- |
16
+
| SAML 2.0 | No | Sign-in happens entirely through the member's browser: the browser is redirected to the IdP, then posts the signed SAMLResponse back to Flashduty after login. Flashduty's servers never connect to the IdP directly — the signature is validated locally against the metadata you upload |
17
+
| OIDC | Yes | On every sign-in, Flashduty's servers fetch the IdP's discovery document, then call its token endpoint and JWKS endpoint. When the ID Token doesn't carry every mapped field, Flashduty also calls the UserInfo endpoint |
18
+
| CAS | Yes | On every sign-in, Flashduty's servers call the IdP's `/serviceValidate` endpoint to validate the login ticket. The CAS protocol offers no alternative — the ticket carries no signed content, so it can only be validated at the source |
19
+
| LDAP | Not applicable | Available only in the private deployment version, where Flashduty runs inside your own network — public internet reachability doesn't apply |
20
+
21
+
If your identity provider is on a private network and not reachable from the public internet:
22
+
23
+
- You can allow Flashduty's egress IPs — `47.94.95.118`, `123.56.8.183`, `47.94.193.81`, and `1.13.19.96` — through your firewall to open access from Flashduty to the IdP
24
+
- If you'd rather not open any public access to your identity provider, **SAML 2.0** is the only protocol that needs none — it's the recommended choice in that case
25
+
26
+
<Note>
27
+
The egress IPs above apply only to Flashduty's **SaaS (public cloud) service**. If you're using a private (on-premises) deployment, Flashduty runs inside your own network and its egress IP depends on your deployment environment — check with your infrastructure team instead of using the addresses above.
0 commit comments