BeyondTrust is a first-class enterprise connection over OpenID Connect. A customer's administrator owns the BeyondTrust side. Authdog routes users by email domain.

## Open the connection

In the [Authdog console](https://console.authdog.com/dashboard/authentication?tab=providers&category=enterprise):

1. Select the project and environment.
2. Open **Authentication > Providers** with the Enterprise filter.
3. Choose **BeyondTrust**.
4. Copy the redirect / callback URL Authdog displays and register it on the BeyondTrust OIDC client as a web redirect URI.

## Configure OIDC

Enter:

| Field | Value |
| --- | --- |
| **Connection name** | A name that shows in the Configured list |
| **OpenID Connect Discovery URL** | The discovery document URL, not a bare issuer that does not serve the document |
| **Client ID** | The OIDC client ID |
| **Authentication Method** | **Client Secret** |
| **Client secret** | Stored encrypted. Leave blank on a later edit to keep the stored secret |

Choose **Private Key JWT** only when BeyondTrust expects a signed JWT instead of a secret. Then provide the **Private Key (PEM)** and **Signing Algorithm** (`RS256`, `RS384`, or `RS512`).

Scopes default to `openid profile email`. Add an extra scope only when a claim you need requires it. Leave **Prompt** on the IdP default unless you need an account picker or a forced re-authentication.

## Route by email domain

In **Email domains (for SSO discovery)**:

```text
acme.com
```

The entry matches that domain and its subdomains. Keep domains from overlapping other enterprise connections in the same environment. Only active connections participate in discovery.

## Test it

1. Use **Test** on the connection.
2. Sign in with a user in the routed domain and confirm the subject and email claims.
3. Repeat in production. If you add a [custom domain](/docs/custom-domains), update the redirect URI BeyondTrust has on file with the URL shown in the form.

Store the client secret only in Authdog and BeyondTrust. Do not put it in browser code.

## Related

| Read | To learn how to |
| --- | --- |
| [Enterprise SSO](/docs/sso) | Discovery, domain routing, and secrets |
| [OpenID Connect](/marketplace/openid-connect/setup) | The same form for an issuer that is not a named vendor |
| [Marketplace](/marketplace/beyondtrust) | The listing for this integration |
