Oracle & Legacy App SSO
Bring Oracle E-Business Suite, PeopleSoft, JD Edwards, Siebel and header-based legacy apps under Keycloak SSO and MFA, through integration paths Oracle supports and without touching application code.
Overview
Oracle applications rarely accept tokens from an arbitrary identity provider, and many legacy web apps only understand an HTTP header or their own login form. We connect them to Keycloak the way each one supports. For E-Business Suite, that means Oracle's EBS Asserter with an OCI IAM identity domain, or Oracle Access Manager with EBS AccessGate, federated to Keycloak over SAML 2.0. PeopleSoft and JD Edwards use native SAML on releases that support it, and Oracle Access Manager or a trusted-header setup on older ones. Siebel web SSO and apps such as Hyperion, OBIEE and Oracle Forms sit behind a hardened identity-aware proxy that strips client-supplied headers. Every identity is mapped to its existing application account, logout and session timeouts are aligned, and the local login page is kept for break-glass access. We confirm each integration path against Oracle's documentation for your exact releases before design.
Delivery Process
What's Included
- Sign-on assessment per application and release
- EBS Asserter / Oracle Access Manager federation to Keycloak
- SAML 2.0 for PeopleSoft and JD Edwards where supported
- Hardened identity-aware proxy for header-based apps
- User ID mapping and reconciliation (FND_USER, PeopleSoft and JDE IDs)
- Cut-over runbook with break-glass and rollback
Timeline & Scope
Timeline
4-8 weeks
Ideal For
Enterprises running Oracle applications or other legacy web apps that need modern SSO and MFA without rewriting them.
Warranty
30-day warranty covering sign-on, user mapping, logout and session-timeout issues discovered after cut-over.
Tech Stack
Related Solutions
Ready to get started?
Fixed price. Clear scope. 30-day warranty.