OpenID Connect Access Provider

Configuration for OpenID Connect for OAuth2 Access Provider to authenticate users for 3DM Publisher Publications.

Workflow

  1. Administrator configures Access Provider, register 3DM Publisher as Client of the Access Provider
  2. Administrator configures 3DM Publisher, delegate user authentication to Access Provider
  3. Administrator configures 3DM Publisher, create Publication and grant user access (Authorization)
  4. User launches 3DM Viewer
  5. User selects 3DM Viewer login option for Access Provider
  6. 3DM Viewer triggers pop-up for the user to identify via the Access Provider
  7. Access Provider provides ID Token with email to the 3DM Viewer (Authentication)
  8. 3DM Viewer transfers ID Token with email to 3DM Publisher for user identification (Authorization)
  9. 3DM Publisher validates ID Token with email with 3DM Publication Authorized Users via 1) user name or 2) user email

Users created within the Orbit Publisher Console can be granted access to publications. Each user is assigned a unique login and password. To streamline user management, multiple users can be imported or updated simultaneously using a .txt or .csv file. For more details, please refer to the documentation: 3DM Publisher Console.

Configure Access Provider to register 3DM Publisher as Client

Every OAuth2 Access Provider holds a list of known Client applications it offers services to.
Your 3DM Publisher Server needs to be registered as Client of the OAuth2 Service, typically the following information is required:

  • App Name: The name of your 3D Publisher Server, usually displayed when asking the user for consent.
    Example: Demo Publisher
  • Application Location: The domain(s) your 3DM Publisher Server is hosted / accessible for end-users.
    Example: https://publisher.orbitgt.com
  • Redirect URL: The URL the Access Provider will redirect to after login is complete.
    Set to: <3DM Publisher Domain>/viewer/assets/oauth-flow-callback.html.
    Example: https://publisher.orbitgt.com/viewer/assets/oauth-flow-callback.html
  • Scopes : The list of scopes the application is allowed to request.
    Set to: openid email profile
  • Application Type: Select the type that enables Authorization Code Flow. Naming differs by Access Provider.
    Set to: Single Page Application (SPA) or Authorization Code Flow.

Notes for Bentley IMS

Additional notes to configure Bentley IMS Access Provider via OpenID Connect for Orbit 3DM Publisher.

A default “Bentley IMS” access provider (managed by Bentley) is added to every new installation, but disabled because your Application Location must be added to complete the configuration.

To enable Bentley IMS, there are 2 options:

  • Complete the default “Bentley IMS” access provider configuration by sharing your Application Location with Bentley Support.
  • Add a new Access Provider based on your own Bentley App registration.
    To register your own Bentley App you need to be a Bentley Developer.
    Manage your App registrations here: https://developer.bentley.com/my-apps/

Notes for Google

Additional notes to configure a Google Access Provider for Orbit 3DM Publisher.

Notes for Azure Entra ID

Additional notes to configure a Azure Entra ID Access Provider for Orbit 3DM Publisher.

  • Create a Single-Page Application (SPA) (not a Web Application).
  • Add the following optional claims on the “Token Configuration” page:
    • email (ID)
    • preferred_username (ID)
  • Orbit 3DM Publisher configurations provided by Azure Entra
    • OIDC Authority URL = https://sts.windows.net/<directory-tentant-id>/ (include the trailing slash)
    • Client ID = <application-client-id>

Configure 3DM Publisher to delegate user authentication

Access Provider configurations are managed from the Publisher Console's, System page.
Once configured and enabled, the 3DM Viewer automatically presents the Access Provider login option to the user.

  • Code: Free of choice unique id of the Access Provider for 3DM Publisher
  • Name: Free of choice name of Access Provider for 3DM Publisher
  • OIDC Authority URL: The authority URL of the OpenID Connect Service, usually its domain.
  • Client ID: The client-id of your 3DM Publisher Client provided by the OpenID Connect Service.
  • Client Secret: The secret of your 3DM Publisher Client provided by the OpenID Connect Service (only required for Google).
  • Login Button Label: Free of choice label of the 3DM Viewer sign-in button.

Implement SSO for Viewer SDK

Implement SSO via Access Providers

Alternative options to achieve an auto-login or no login experience:

 
Last modified:: 2026/07/16 17:53