KeycloakPro

Legacy App SSO · PeopleSoft

PeopleSoft SSO with Keycloak

HCM, Financials, Campus Solutions and Interaction Hub behind one Keycloak login with MFA — using the native SAML 2.0 support added in PeopleTools 8.63, or Signon PeopleCode behind a hardened proxy on earlier releases.

  • Native SAML 2.0 on PeopleTools 8.63
  • Signon PeopleCode for earlier releases
  • MFA before users reach PeopleSoft

Standards & integrations

  • SAML 2.0
  • PeopleTools 8.63
  • Signon PeopleCode
  • PS_TOKEN
  • Oracle Access Manager
  • LDAP / Active Directory

Overview

PeopleTools 8.63 changes how PeopleSoft SSO works

Before PeopleTools 8.63, PeopleSoft had no native way to accept a SAML assertion: single sign-on meant an access manager or reverse proxy authenticating the user and passing a trusted identity that Signon PeopleCode maps to a PeopleSoft user ID. PeopleTools 8.63 adds a native SAML 2.0 framework with identity provider- and service provider-initiated sign-on. It became generally available on Oracle Cloud Infrastructure on July 29, 2026, with on-premises availability to follow. We design for the release each environment runs today and plan the move to native SAML as you upgrade.

What we deliver

  • Sign-on option assessment per PeopleSoft environment
  • Keycloak realm and SAML client configuration
  • Native SAML (PeopleTools 8.63) or Signon PeopleCode configuration
  • Reverse proxy with header hardening, where needed
  • User ID mapping and reconciliation
  • Rollout and rollback runbook per pillar

Capabilities

What PeopleSoft covers

Configured, tested and documented on upstream Keycloak — then handed over or operated by us.

  • Native SAML on PeopleTools 8.63

    PeopleSoft acts as a SAML 2.0 service provider that trusts Keycloak, with identity provider- and service provider-initiated sign-on — no gateway in the path.

  • Signon PeopleCode on earlier releases

    Before 8.63, a SAML- or OIDC-aware reverse proxy authenticates users at Keycloak and passes a trusted identity that Signon PeopleCode maps to a user.

  • User ID mapping

    Keycloak identities map to PeopleSoft user IDs by employee ID, username or email, with conflicts resolved before go-live.

  • Spoof-proof trusted headers

    The web tier only accepts traffic from the proxy, which strips any client-supplied identity headers — the classic weakness of header-based SSO.

  • One sign-on across pillars

    Once a user is in, PeopleSoft's PS_TOKEN carries the session between trusted pillars, so users move from HCM to Financials without signing in again.

  • MFA, Entra ID and Okta sign-in

    OTP, passkeys or push are enforced at Keycloak, which can also broker Entra ID, Okta or Active Directory, with a stricter flow for internet-facing self-service.

Compatibility

PeopleSoft sign-on options

What we use depends on the PeopleTools release of each environment, confirmed during the assessment.

PlatformIntegrationNotes
PeopleTools 8.63Native SAML 2.0 service providerIdP- and SP-initiated sign-on; generally available on OCI, with on-premises availability to follow.
PeopleTools 8.62 and earlierReverse proxy + Signon PeopleCodeThe proxy authenticates at Keycloak and passes a trusted identity to the web tier.
Environments behind Oracle Access ManagerOAM federated to Keycloak over SAML 2.0Keeps existing WebGates in place while Keycloak becomes the IdP.
Interaction HubSame SSO session across pillarsPS_TOKEN carries the session once every pillar trusts the same sign-on.
Integration Broker and web servicesOutside browser SSOService-to-service calls keep their own authentication; we review them separately.

How it works

From first call to production

  1. Inventory environments and releases

    We record the PeopleTools release, web server and current sign-on method of every environment and choose native SAML or Signon PeopleCode for each.

  2. Configure and test outside production

    Keycloak, the SAML or proxy configuration and user mapping are built in a non-production environment and tested for login, timeouts and sign-out.

  3. Roll out pillar by pillar

    Each pillar moves in its own window with a rollback path, starting with the lowest-risk user population, and switches to native SAML when it reaches 8.63.

Use cases

Where teams put it to work

  • Employee self-service online

    Protect HCM self-service with MFA when it's reachable from outside the corporate network.

  • Campus and student portals

    Students and staff use the institution's central login for Campus Solutions and the other systems they rely on.

  • Planning a PeopleTools 8.63 upgrade

    Move to Keycloak now with Signon PeopleCode, then switch each environment to native SAML as it upgrades — without users noticing.

FAQ

PeopleSoft questions, answered

Does PeopleSoft support SAML natively?

From PeopleTools 8.63, yes — it adds a native SAML 2.0 framework with identity provider- and service provider-initiated sign-on. Earlier releases have no native SAML sign-on, so SSO relies on Signon PeopleCode reading a trusted identity from an access manager or proxy.

What changed with PeopleTools 8.63?

8.63 is the first PeopleTools release with native SAML 2.0 sign-on. It became generally available on Oracle Cloud Infrastructure on July 29, 2026, with on-premises availability announced to follow. We can run Keycloak with Signon PeopleCode today and switch environments to native SAML as they move to 8.63.

What is PS_TOKEN, and is it enough for SSO?

PS_TOKEN is the cookie PeopleSoft uses to carry a signed-in session between PeopleSoft applications that trust each other. It handles SSO inside PeopleSoft, but it can't authenticate users against Keycloak or enforce MFA — that still needs SAML or Signon PeopleCode.

Can PeopleSoft users sign in with Entra ID or Okta?

Yes. Keycloak brokers Entra ID, Okta or Active Directory, and PeopleSoft trusts Keycloak — over SAML on PeopleTools 8.63, or through the proxy and Signon PeopleCode on earlier releases.

Do we need Oracle Access Manager?

No. OAM is one way to give PeopleSoft a trusted identity, but native SAML on PeopleTools 8.63 or a hardened reverse proxy on earlier releases works with Keycloak without it.

Is header-based SSO safe?

It is when only the proxy can reach PeopleSoft's web tier and the proxy removes any identity headers sent by the browser. We lock down both and test for header injection before go-live.

Ready to roll out PeopleSoft?

Walk us through your requirements on a free strategy call. We'll come back with an architecture, a delivery plan and a fixed scope.

Browse all solutions