Elevate ร— IDHub
๐Ÿงช Integration Playground
B2B Identity Platform โ€” Capability Overview

IDHub for Elevate

Everything Elevate needs from IDHub โ€” organization management, authentication, entitlements, and self-service โ€” mapped to your requirements and ready to explore.

๐Ÿงช Open Playground
Realm: b2b  โ€ข  OIDC + PKCE  โ€ข  LoginUI on port 3002
๐Ÿ“Š Capability Coverage
8 Live
3 Ready
3 Planned
Live Demo โ€” try it now in the playground Architecture Ready โ€” designed & configured, pending full integration Planned โ€” architecture designed, implementation scheduled
E1 Architecture Ready

Bulk Organization Import

Load 8,000+ organizations (pharmacies, hospitals, distributors) from SAP before user onboarding begins.

E2 Try It Now

Per-Org Corporate SSO

Organizations with their own IdP (Azure AD, Okta) get automatic redirect โ€” users never see the default login form.

E3 Try It Now

First User Becomes Admin

First person to register at an org with no members is automatically promoted to organization administrator.

E4 Try It Now

Default Role Assignment

New members get a configurable default role upon joining, or can choose from available self-registrable roles.

E5 Try It Now

Realm-Level Role Templates

Roles defined once at realm level, inherited by all 8K+ organizations โ€” no per-org role duplication.

E6 Try It Now

Multi-Module Access, Single Auth

One OIDC login โ†’ JWT with per-module permissions. Portal, Club Bayer, and My-Orders gated from one token.

E7 Architecture Ready

Attribute-Based App Access

Access to My-Orders requires billing/shipping address โ€” determined by attributes, not just role.

E8 Planned

Organization Discovery

If email domain doesn't match, users can search for their org or request a new one to be created.

E9 Architecture Ready

Mandatory Member Attributes

Org-level mandatory attributes for ALL members (e.g., billing address), regardless of role.

E10 Planned

Approval Workflow Toggle

Enable/disable approval workflows realm-wide in bulk โ€” no per-org configuration needed.

E11 Try It Now

Rule-Based Role Assignment

Automatic role assignment from attributes โ€” e.g., businessType = "wholesaler" โ†’ wholesaler role with My-Orders access.

E12 Try It Now

Realm-Level Attribute Schemas

Member attribute definitions shared across all orgs โ€” one change applies everywhere.

E13 Planned

Org-Level Settings Override

Specific organizations can override realm defaults (e.g., disable approval for VIP orgs).

E14 Try It Now

Custom Token Mappers

Per-client custom claims injected into JWTs at issuance โ€” department, tags, computed values, and extra audiences โ€” configured in MGM, evaluated server-side.

โšก Quick Start

Test Accounts

EmailWhat Happens
demo@yopmail.comAuto-join Munich Pharma (Gigya auth)
demo@byom.deMulti-org selector โ€” pick Acme Hospital or Berlin Med
dr.mueller@berlin-med.deCorporate SSO via Keycloak, pw: test1234
demo@hamburg-bio.deAuto-join Hamburg Biotech (Gigya auth)
demo@gmail.comNo org match โ€” continue without organization

Service URLs

ServiceURL
Elevate Simulatorlocalhost:3003
LoginUI (OIDC)localhost:3002
MyAccountlocalhost:3000
MGM Applocalhost:3001 (localadmin / localadmin)
Keycloak Adminlocalhost:8080/admin (admin / admin)