Hello there!

Need Help? We are right here!

Support Icon
miniOrange Email Support
success

Thanks for your Enquiry. Our team will soon reach out to you.

If you don't hear from us within 24 hours, please feel free to send a follow-up email to info@xecurify.com

Search Results:

×

BigCommerce B2B Social Login SSO


BigCommerce Partner logo

BigCommerce B2B Social Login allows business buyers to create an account or log in to your BigCommerce B2B store using their existing social or enterprise identity credentials, such as Google, Microsoft, Apple, Facebook, or other supported Identity Providers (IdPs). This simplifies the authentication process for B2B buyers by eliminating the need to remember separate BigCommerce login credentials.

With BigCommerce B2B Social Login, you can:

  • Enable B2B buyers to securely log in to your BigCommerce B2B storefront using their existing social or Identity Provider credentials.
  • Simplify access for business buyers while maintaining their B2B company and user-role associations.
  • Improve the B2B buying experience by providing faster, passwordless-style access to the storefront and reducing login friction.
  • Enhance security by integrating Multi-Factor Authentication (MFA/2FA) with the authentication flow.

Verified Technology Partner of BigCommerce

Social Login Support for any BigCommerce Plan (Standard, Plus, Pro, Enterprise)


Get Free Installation Help


miniOrange offers free help through a consultation call with our System Engineers to Install or Setup BigCommerce SSO solution in your environment with 30-day free trial.

For this, you need to just send us an email at idpsupport@xecurify.com to book a slot and we'll help you in no time.


Checkout Pricing


Video Setup Guide



Connect with External Source of Users


miniOrange provides user authentication from various external sources, which can be Directories (like ADFS, Microsoft Active Directory, OpenLDAP, AWS etc), Identity Providers (like Microsoft Entra ID, Okta, AWS), and many more. You can configure your existing directory/user store or add users in miniOrange.



Prerequisites

Please make sure your organisation branding is already set under Customization >> Login and Registration Branding in the left menu of the dashboard.


Follow the Step-by-Step Guide given below for BigCommerce Single Sign-On (SSO)

1. Create BigCommerce API

  • Log in to BigCommerce Admin Panel.
  • Go to the Settings from the sidebar, scroll down to API and then click on Store-level API accounts.
  • BigCommerce Social Login SSO: API account

  • Click on Create API Account and choose the token type as V2/V3 API Token option from the menu shown.
  • BigCommerce Social Login SSO: Create API account

  • Add a suitable name for your API account.

    Note: In BigCommerce, the API Path is the base URL that your application or integration uses to connect to your store’s data through BigCommerce APIs. The Store Hash is a unique identifier automatically generated by BigCommerce for each store. It appears in the API Path.

  • Copy the highlighted Store Hash from the API Path.
  • BigCommerce B2B Social Login SSO:: API Path

    BigCommerce B2B Social Login SSO:: Enable Option

    Note: This Store Hash will be required while configuring BigCommerce in miniOrange.

  • Enable the Customers option as Modify, set Customers Login to Login, and enable B2B Edition as Modify. Keep all other settings unchanged.
  • Click on Save.
  • Download the API credentials file. It contains the API token, Client ID and Client Secret.
  • BigCommerce Social Login SSO:: API Credential Download

2. Configure BigCommerce in miniOrange

  • Login into miniOrange Admin Console.
  • Go to Apps, click on Add Application button.
  • BigCommerce Single Sign On (SSO) Login add app

  • In the Choose Application section, open the dropdown list of All Apps and select JWT.
  • BigCommerce B2B Single Sign On (SSO): choose JWT as app type

  • In the next step, search for BigCommerceB2B application from the list and click on it.
  • BigCommerce B2B Single Sign On (SSO): Select BigCommerce Application

  • Enter the following values in the respective fields.
  • BigCommerce B2B Single Sign On (SSO): Enter Basic details

  • Enter the Client ID, Client secret and Access token which we have downloaded from step 1 during API creation in BigCommerce Console.
    Display Name [Required] BigCommerce (According to your choice)
    Description According to your choice
    Redirect-URL [Required] Storefront URL/login/token/eg.https://{{my-store}}.mybigcommerce.com/login/token/
    Client ID Copy from the downloaded file in Step 1
    Client Secret Copy from the downloaded file in Step 1
    Access Token Copy from the downloaded file in Step 1
  • Note: Your Redirect URL should be: <Storefront URL>/login/token/
    For Example: https://mystore.mybigcommerce.com/login/token/

    To find your Storefront URL: Go to Channels >> Storefronts. Copy the URL listed for your store.

    BigCommerce B2B Single Sign-On (SSO): Go to Channels > Storefronts and copy listed URLs


  • Now click on Next and go to Advanced tab.
  • BigCommerce B2B Single Sign On (SSO): Switch to Advanced tab

    Subject E-Mail Address.
    Signature Algorithm HS256
    Logout URL Copy the storefront URL as mentioned above and append /login.php?action=logout
    BigCommerce SSO: Logout URL field - e.g. https://your-store/login/token/
  • Click Next to go to the Login Options tab.
  • BigCommerce B2B Single Sign On (SSO): Go to Login Options

    Primary Identity Provider The identity source against which user will be authenticated
    Force Authentication Enable if you want user to authenticate even if the user has a session
    Enable User Mapping Enable if you are sending the logged-in user from this app in the response
  • Click on the Save button.
  • For Attribute Mapping and add new attributes, navigate to the Attributes tab and click on the Add Attribute.
  • To map the attributes between the IDP and BigCommerce application, click on Attributes + button.
  • The first three attributes will be hard-coded values
    Attribute NameAttribute TypeAttribute Value
    store_hashCustom Attribute ValueRefer to Step 1 above.
    redirect_toCustom Attribute ValueEndpoint where you wish to redirect the user to after sso.
    [Homepage or account page e.g. /account.php]
    operationCustom Profile Attributecustomer_login
    first_nameExternal Idp Attributefirst_name
    last_nameExternal Idp Attributelast_name
    emailExternal Idp Attributeemail
    companyNameMap to company field or static value[Company name for B2B account] TestCompany
  • BigCommerce B2B Single Sign On (SSO): Map custom attributes

  • Click on the Save button.

Configure Optional Attributes

  • Beyond the required attributes, you can configure additional optional attributes to customize user provisioning and company setup.
  • Available Optional Attributes

    Attribute Description Accepted Values Default Value
    role User's role within the B2B company admin, senior_buyer, junior_buyer junior_buyer
    phone Company contact phone number Valid phone number string 1234567890
    country Company's primary business location Full country name or two-letter country code (e.g., 'United States', 'US', 'Canada', 'CA') United States

    How to Add Optional Attributes

    • In the Attribute tab, click Add Attribute Mapping.
    • Enter the attribute name exactly as shown above (case-sensitive).
    • Map it to the corresponding field from your identity provider, or enter a static value.
    • Click on Save.
    Bigcommerce SSO: Add optional Attribute

    Important Notes About Optional Attributes

    • First User Exception: The first user created for any company will automatically receive the admin role, regardless of the role attribute mapping. This ensures each company has at least one administrator.
    • Phone Format: Any phone number format is accepted.
    • Country Names: Use full country names as they appear in BigCommerce (e.g., "United States" not "US" or "USA").
    • Defaults Applied: If optional attributes are not configured, the system will use the default values listed above. The integration will function normally without them.
  • Navigate to Policies tab.
  • Click on Assign Group button.
  • BigCommerce B2B Single Sign On (SSO): Navigate to Policies and click Assign Group

  • Choose the DEFAULT group.
  • Click on the Next button.
  • BigCommerce B2B Single Sign On (SSO): Choose Default as group

  • Assign the policies to the group. Here, you can choose the primary authentication method for users. From the dropdown under First Factor, select Password.
  • BigCommerce B2B Single Sign On (SSO): Select First Factor as Password

  • Click on the Save button.

3. Configure Social Login Providers

miniOrange provides user authentication from various external sources, which can be Directories (like ADFS, Microsoft Entra ID, OpenLDAP, Google, AWS Cognito etc), Identity Providers (like Okta, Shibboleth, Ping, OneLogin, KeyCloak), Databases (like MySQL, Maria DB, PostgreSQL) and many more. You can configure your existing directory/user store or add users in miniOrange.



Step 3.1: Configure Google Apps as OAuth 2.0 Provider in miniOrange.

  • Go to miniOrange Admin Console.
  • From the left navigation bar select Identity Providers.
  • Click on Add Identity Provider.
  • BigCommerce Social Login Single Sign-On: Click Identity Providers > Add Identity Provider

  • Click on Add Social Connection.
  • BigCommerce Social Login Single Sign-On: Click Add Social Connection

  • Click on the Google Social App option and then click on Enable Connection.
  • BigCommerce Social Login Single Sign-On: Check Google and click Enable Connection

  • Your connection will be configured and will get added to the External Identity Providers list.
  • BigCommerce Social Login Single Sign-On: Added Successful Google as Social App

  • Go to the Apps section from the sidebar on the miniOrange Dashboard.
  • Select the app that you have configured.
  • Click on Edit under the Actions column.
  • Navigate to the Login Options tab.
  • Select Google as the Identity Provider.
  • Click Save to apply the changes.
  • BigCommerce Social Login Single Sign-On: Select Google as Identity Provider

  • Go to the Endpoints tab and copy the SSO URL used for authentication via the external IdP.
  • BigCommerce Social Login Single Sign-On: Go to Endpoints tab and copy SSO URL

  • Paste the copied URL into an incognito window to test the login flow.
  • BigCommerce Social Login Single Sign-On: Test Login Flow


Step 3.1: Configure LinkedIn as OAuth 2.0 Provider in miniOrange

  • Go to miniOrange Admin Console.
  • From the left navigation bar select Identity Providers >> Add Identity Provider.
  • BigCommerce Social Login Single Sign-On: Click Identity Providers > Add Identity Provider

  • Click on Add Social Connection.
  • BigCommerce Social Login Single Sign-On: Add Social Connection

  • Click on the Linkedin Social App option and then click on Enable Connection.
  • BigCommerce Social Login Single Sign-On: Check LinkedIn and Enable Connection

  • Your connection will be configured and will get added to the External Identity Providers list.
  • BigCommerce Social Login Single Sign-On: Added successful LinkedIn as Social App

  • Go to the Apps section from the sidebar on the miniOrange Dashboard.
  • Select the app that you have configured.
  • Click on Edit under the Actions column.
  • Navigate to the Login Options tab.
  • Select LinkedIn as the Identity Provider.
  • Click Save to apply the changes.
  • BigCommerce Social Login Single Sign-On: Select LinkedIn as Identity Provider

  • Go to the Endpoints tab and copy the SSO URL used for authentication via the external IdP.
  • BigCommerce Social Login Single Sign-On: Go to Endpoints tab and copy SSO URL

  • Paste the copied URL into an incognito window to test the login flow.
  • BigCommerce Social Login Single Sign-On: Test the login flow

Step 3.1: Configure Facebook as OAuth 2.0 Provider in miniOrange

  • Go to miniOrange Admin Console.
  • From the left navigation bar select Identity Providers >> Add Identity Provider.
  • BigCommerce Social Login Single Sign-On: Add Identity Provider

  • Click on Add Social Connection.
  • BigCommerce Social Login Single Sign-On: Add Social Connection

  • Click on the Facebook Social App option and then click on Enable Connection.
  • BigCommerce Social Login Single Sign-On: Check Facebook and Enable Connection

  • Your connection will be configured and will get added to the External Identity Providers list.
  • BigCommerce Social Login Single Sign-On: Added successful Facebook as Social App

  • Go to the Apps section from the sidebar on the miniOrange Dashboard.
  • Select the app that you have configured.
  • Click on Edit under the Actions column.
  • Navigate to the Login Options tab.
  • Select Facebook as the Identity Provider.
  • Click Save to apply the changes.
  • BigCommerce Social Login Single Sign-On: Select Facebook as Identity Provider

  • Go to the Endpoints tab and copy the SSO URL used for authentication via the external IdP.
  • BigCommerce Social Login Single Sign-On: Go to Endpoints and copy SSO URL

  • Paste the copied URL into an incognito window to test the login flow.
  • BigCommerce Social Login Single Sign-On: Test the login flow

Step 3.1: Configure Apple Apps as OAuth 2.0 Provider in miniOrange

  • Go to Apple Developer.
  • Click Account.
  • Sign in with your Apple Developer credentials.
  • Open Certificates, Identifiers & Profiles.
  • Click Certificates.
  • BigCommerce Social Login Single Sign-On: Apple Developer Certificates

  • Click Identifiers in the left menu, then click the blue plus (+) icon to add a new identifier.
  • BigCommerce Social Login Single Sign-On: Identifiers and add new identifier

  • On the Certificates, Identifiers & Profiles page, click Continue.
  • BigCommerce Social Login Single Sign-On: Continue on Certificates Identifiers Profiles

  • On the next screen (Register a new identifier >> Select a type), ensure that App is selected. Click the Continue button again to proceed to the next step.
  • BigCommerce Social Login Single Sign-On: Register new identifier App type

  • Enter a Description and Bundle ID for the App ID.
  • For example: Description: MiniorangeSPApp, Bundle ID: com.miniorange.spapp
  • BigCommerce Social Login Single Sign-On: App ID description, Bundle ID example, and Continue

  • In the Capabilities section, scroll down and select Sign in with Apple.
  • BigCommerce Social Login Single Sign-On: Sign in with Apple capability

  • Click Edit, choose Enable as a primary App ID, then click Save.
  • BigCommerce Social Login Single Sign-On: Primary App ID and Save

  • Click Continue in the top-right corner.
  • BigCommerce Social Login Single Sign-On: App ID summary with Continue in top right

  • Click on the Register.
  • BigCommerce Social Login Single Sign-On: Sign in with Apple capability and Register for App ID

  • Click Identifiers in the left menu, then click the blue plus (+) icon.
  • BigCommerce Social Login Single Sign-On: Identifiers and add new identifier

  • Select Services IDs, then click Continue.
  • BigCommerce Social Login Single Sign-On: Service IDs continue

  • Enter the Description and Identifier (the Identifier will serve as your Client ID - copy this value, as it will be required in later steps).
  • BigCommerce Social Login Single Sign-On: Service ID description and identifier

  • Click Continue, then Register.
  • BigCommerce Social Login Single Sign-On: Continue and Register Service ID

  • In the left sidebar, click Keys, then click the plus (+) icon to create a new key.
  • BigCommerce Social Login Single Sign-On: Keys section

  • Enter a Key Name.
  • BigCommerce Social Login Single Sign-On: Key name

  • Enable Sign In with Apple, then click Configure.
  • BigCommerce Social Login Single Sign-On: Sign in with Apple and Configure

  • Select the Primary App ID that you configured previously, then click Save.
  • BigCommerce Social Login Single Sign-On: Primary App ID Save

  • In the top-right corner, click Continue.
  • BigCommerce Social Login Single Sign-On: Continue top right

  • Click on the Register button.
  • BigCommerce Social Login Single Sign-On: Register key

  • Click the Download button to download the key (the file will have a .p8 extension).
  • BigCommerce Social Login Single Sign-On: Download p8 key

  • After the key has downloaded, click Done.
  • BigCommerce Social Login Single Sign-On: Keys list after downloading .p8 key, click Done

  • Click Identifiers from the left menu, then click App IDs at the top right and select Service IDs from the drop-down menu.
  • BigCommerce Social Login Single Sign-On: App IDs Services IDs

  • Select the previously configured Identifier, then select Sign In with Apple and click the Configure button.
  • BigCommerce Social Login Single Sign-On: Configure Sign in with Apple

  • Select your Primary App ID from the drop-down.
  • Enter the Domain in the Domains and Subdomains section.
  • Enter the OAuth Callback URL from step 4.2 in the Return URLs section.
  • Click on the Next button.
  • BigCommerce Social Login Single Sign-On: Domain and Return URLs

  • Verify the details and click on the Done button.
  • BigCommerce Social Login Single Sign-On: Verify Service ID details

  • At the right corner, click on the Continue button.
  • BigCommerce Social Login Single Sign-On: Continue top right Service ID

  • Click on the Save button at the top right corner.
  • BigCommerce Social Login Single Sign-On: Save Service ID

  • Now follow below steps to generate the client secret key:
  • Generate the client secret (JWT) using Node.js:
  • Download and install Node.js from the following link.
  • Copy the code below into a file and save it with a .js extension. Make sure to keep this .js file and the downloaded .p8 key file in the same folder.
  •   
         const fs = require('fs');
          const jwt = require('jsonwebtoken');
    
    // ===== CONFIGURATION =====
    const TEAM_ID = 'enter_your_TEAM_ID'; // Apple Team ID (iss)
    const CLIENT_ID = 'enter_your_CLIENT_ID '; // Service ID (sub)
    const KEY_ID = 'enter_your_KEY_ID'; // Key ID (kid)
    const PRIVATE_KEY_PATH = 'enter_your_PRIVATE_KEY_PATH'; // Make sure filename matches
    
    // ===== READ PRIVATE KEY =====
    const privateKey = fs.readFileSync(PRIVATE_KEY_PATH, 'utf8');
    
    // ===== TIME SETTINGS =====
    const now = Math.floor(Date.now() / 1000);
    const payload = {
      iss: TEAM_ID,
      iat: now,
      exp: now + (60 * 60 * 24 * 180), // 180 days (max allowed)
      aud: 'https://appleid.apple.com',
      sub: CLIENT_ID
    };
    
    // ===== GENERATE JWT =====
    const clientSecret = jwt.sign(payload, privateKey, {
      algorithm: 'ES256',
      keyid: KEY_ID // important: use keyid instead of custom header object
    });
    
    console.log('\n=== Apple Client Secret ===\n');
    console.log(clientSecret);
      
    

  • Now replace below values in the code as given below:
    • key_file: AuthKey_(enter_your_AUTHKEY) , give it the name of the downloaded .p8 file.
    • Key_id: It will be the Key ID you will get from your configured Key.
    • BigCommerce Social Login Single Sign-On: Apple Developer Key ID

    • Client_id: It is the identifier.
    • Team_id: You will get this from top right corner as shown below.
    • BigCommerce Social Login Single Sign-On: Apple Developer Team ID

  • Go to the folder location in the command prompt which consists of the rb and p8 file. Now run the above code using the following command: node yourfilename.js
  • BigCommerce Social Login Single Sign-On: Run Node script

  • You will receive a Client Secret Key. copy and securely store this key, as it will be required while configuring Apple ID in the miniOrange Dashboard.

Step 3.2: Configure Apple ID as OAuth 2.0 Provider (IDP) in miniOrange

  • Log in to the miniOrange Admin Console.
  • Go to Identity Providers and click Add Identity Provider.
  • BigCommerce BigCommerce as SAML IDP: Add Identity Provider

  • Select OAuth/OpenID as the Identity Provider type.
  • BigCommerce Social Login Single Sign-On: Select OAuth OpenID

  • Click the Apple logo to choose Apple as the Identity Provider.
  • BigCommerce Social Login Single Sign-On: Select Apple IdP

  • Enter the Client ID and Client Secret that you generated in the above steps, and then click on the Save button.
  • BigCommerce Social Login Single Sign-On: Apple OAuth app details

  • Go to the Advanced tab and enable the checkbox for Enable the End User Login, as this is required for JIT mapping later.
  • BigCommerce Social Login Single Sign-On: Advanced tab End User Login

  • Now select the Identity Provider you configured. In the Action column, click on the three dots, and then select Attribute Mapping.
  • BigCommerce Social Login Single Sign-On: Identity Provider actions menu and Attribute Mapping

  • In the Attribute Type section, select External, and configure the attributes such as First Name, Last Name, and Email as shown in the image below and click on the save button.
  • BigCommerce Social Login Single Sign-On: External attribute mapping

  • Additionally, you also need to configure the Attribute Type as User. This is required because Apple provides the First Name and Last Name only during the first SSO login. From the second SSO onwards, Apple does not send these attributes again.
  • BigCommerce Social Login Single Sign-On: User attribute mapping

  • However, BigCommerce requires the attributes first_name, last_name, and email during every login/SSO request, and these attributes are mandatory. To handle this situation, we need to store the user's First Name and Last Name in miniOrange during the first SSO login.
  • This can be achieved using JIT (Just-In-Time) attribute mapping. During the first login, the attributes received from Apple will be stored in miniOrange. From the second login onwards, miniOrange will retrieve these stored attributes and pass them during SSO, ensuring that the required attributes are always available.
  • Now select the Identity Provider you configured. In the Action column, click on the three dots, and then select Test Connection.
  • BigCommerce Social Login Single Sign-On: Test Connection

  • You will be directed to enter your Apple Id.
  • BigCommerce Social Login Single Sign-On: Apple ID sign-in for Test Connection

  • On entering valid Apple credentials you will see a pop-up window which is shown in the below screen.
  • Hence your configuration of Apple as IDP in miniOrange is successfully completed.
  • BigCommerce Social Login Single Sign-On: Test Connection successful

4. Embed your social login urls to perform SP Initiated Social Login

  • Copy the Single Sign-On (SSO) url from the BigCommerce App that you have configured in miniOrange.
  • Just add an identifier such as google_oauth, facebook_oauth, linkedin_oauth, appleid_oauth after your customerId in SSO Url for respective Social login url as given below.
  • Social Login URLs:
    • Google:
      https://{{branding}}.xecurify.com/moas/broker/login/jwt/{customerID}/google_oauth?client_id=yourclientID&redirect_uri=https://storeurl.bigcommerce.com/login/token/
    • Facebook:
      https://{{branding}}.xecurify.com/moas/broker/login/jwt/{customerID}/facebook_oauth?client_id=yourclientID&redirect_uri=https://storeurl.bigcommerce.com/login/token/
    • LinkedIn:
      https://{{branding}}.xecurify.com/moas/broker/login/jwt/{customerID}/linkedin_oauth?client_id=yourclientID&redirect_uri=https://storeurl.bigcommerce.com/login/token/
    • Apple Id:
      https://{{branding}}.xecurify.com/moas/broker/login/jwt/{customerID}/appleid_oauth?client_id=yourclientID&redirect_uri=https://storeurl.bigcommerce.com/login/token/
  • Go to the BigCommerce Admin Panel and then Storefront >> Themes >> Customize.
  • BigCommerce Single Sign-On (SSO): Go to Storefront > Themes > click Customize

  • Choose Button and drag where you want to place.
  • BigCommerce Single Sign-On (SSO): Select Button and drag it where you want

  • Click on the button and give it a name of your choice (e.g., Google SSO).
  • In the button link field, paste the newly generated social login URL with the identifier, then save and publish the changes.
  • BigCommerce Single Sign-On (SSO): Enter the name and paste newly generated social login url

  • Now go back to your storefront, and you will see the button. When you click on it, the SSO will work.
  • BigCommerce Single Sign-On (SSO): Go back to Storefront and see the button

    BigCommerce Single Sign-On (SSO): Wnen you click on it, the sso will work

5. Configure SLO in BigCommerce

  • Download the script to initiate SLO in BigCommerce.
  • Navigate to Storefront >> Script Manager.
  • Click on create a script and add the script file which you have downloaded earlier in the footer of the page.
  • BigCommerce Social Login SSO: create script

  • Enable settings as given in the image below:
  • BigCommerce Social Login SSO: enable settings

  • A text box will be opened where you can add the downloaded script.
  • BigCommerce Social Login SSO: Script contents

Frequently Asked Questions (FAQs)

Can I log into BigCommerce using Microsoft Entra ID / Okta / Auth0 credentials?

Yes, we support SSO into BigCommerce using Microsoft Entra ID, Okta and Auth0 credentials.

Are the users automatically synced into BigCommerce during SSO or should the user exist on BigCommerce as well?

If the user does not exist in your bigcommerce store, our SSO solution will automatically create the user on bigcommerce and perform a seamless login.

Do you support social login for BigCommerce?

Yes, we support social login providers such as google, facebook, twitter and many more. You can set up your Social login app by following the guide here : https://www.miniorange.com/iam/login-with-external-idp/

Is miniOrange's social login SSO supported on all BigCommerce plans?

miniOrange BigCommerce Social Login SSO solution is available for all BigCommerce plans, including the free ones. We also offer support for a wide range of social login providers, including Google, Facebook, Twitter, and more. With our solution, customers can easily log in to their BigCommerce accounts using their preferred social media credentials, while website owners can benefit from increased engagement & streamlined login processes.


External References

Want To Schedule A Demo?

Request a Demo
  




Our Other Identity & Access Management Products