When a user logs into a platform application with their SSO provider, the
first step that should be taken is to see if that user already exists from a
previous login attempt where a Box user record was already created.
If a Box user is found you should
,
or make , to access Box
APIs as that user.
If a Box user is not found you should create a new user with an association to
the SSO user record.
To search for existing users the
endpoint may be used. Depending on whether you’re using the
external_app_user_id or login method your query will look slightly
different.
Choose the search method that matches how you originally associated the SSO
identity to the Box user in
:
- Use
external_app_user_id if you stored the SSO provider’s unique ID on the Box user. This works for both app users and managed users.
- Use the
login email if you created a managed user whose login is the SSO email address.
Find user by external app user ID
To search for enterprise users by the stored external_app_user_id value you
will need one piece of information from the SSO provider:
- UID (required): The unique identifier from the SSO user record.
Once available, make a request to the list enterprise users endpoint, supplying
the external_app_user_id definition in the parameters.
You can retrieve app users for a specific application only if
such app users were created by this application.
If you use one application to search for users
created by a different one, no data will be returned.
Find user by email address
To search for enterprise users by their login email you
will need one piece of information from the SSO provider:
- Email (required): The unique email from the SSO user record.
Once available, make a request to the list enterprise users endpoint, supplying
the email address as the filter_term, which is made available to search by
email or name.