On November 30th, 2019, Vendasta depreciated older versions of single sign-on. This means any existing partners leveraging single sign-on must transition to V3 prior to this date.
For up-to-date quickstart guides, links to SDKs, API references, configuration
instructions and more, visit: https://www.vendasta.com/developers/partners/sso
If you’re unsure of which version of SSO you’re currently using through Vendasta, please contact support@vendasta.com.
Why must I upgrade?
Security
Vendasta V3 SSO is more secure than V1 and V2. Previous versions of SSO utilized signed URLs to move a user to a service provider. During this process, a signature would be placed in the URL to be validated by the service provider, and then the user would be given a session. V3 SSO uses three-legged OAuth to accomplish session transfer between identity providers and service providers. Identity providers specify the user that moves to the service provider; the data is passed to the service provider via JSON Web Token (JWT) to ensure there’s no data tampering. The service provider will give the identity provider a code that the user can use to claim their session once the user has moved to the service provider.
V3 SSO operates around users rather than business accounts. When session transfer occurs, a user's session will be moved to a service provider. This allows the app to better scope permissions.
Ease of future product diversification
Product diversification is your key to client retention and business growth. This is why Vendasta developed Marketplace: a source of curated, risk-free, instant-on apps and services for SEO, Social, Video, Advertising, Websites, and more. We’ve also looked at over 200k SMBs in the Vendasta platform, and have discovered that companies providing their clients with only one product have an average retention rate of only 30% after two years, whereas clients with four products or more sees a retention rate of 80%. (Source: Why Your Clients Churn).
The need to diversify is clear, yet the technical barriers of developing, integrating, and diversifying products are ultimately too time-consuming for many Vendasta resellers. That’s where integration with a wholesale marketplace of resellable digital solutions comes in to play. Integrating your dashboard via SSO with the Vendasta Marketplace ensures that you have all existing and future Marketplace products & services available to start selling immediately. This means bringing new products and revenue streams to your market becomes a business decision, not a technical barrier. In other words, no more battling with developer roadmaps, maintaining excess code, or developing one-off technical integrations. Adding brand new products to your core product line becomes as simple as adding a link in your dashboard and flipping an account switch. Skip the technical integration, skip the RFPs, skip the vendor clutter, and consolidate with one bill directly from Vendasta.
What will happen if I do nothing?
When V1 & V2 SSO are deprecated on November 30th, 2019, any apps or services still using these resources will pose a security risk. If you currently rely on an integration that makes requests using V1 or V2 resources, you should update it to use V3 as soon as possible.