website/integrations/miscellaneous/amazon-business/index.mdx
Amazon Business is Amazon's procurement platform for organizations, providing managed purchasing, approval workflows, and analytics across Amazon's marketplace.
The following placeholders are used in this guide:
authentik.company is the FQDN of the authentik installation.:::info This documentation lists only the settings that you need to change from their default values. Be aware that any changes other than those explicitly mentioned in this guide could cause issues accessing your application. :::
:::info Domain verification Amazon Business SSO works without first verifying your domain. For seamless onboarding and auto-provisioning, Amazon recommends completing Domain verification (found under System integrations) before configuring SSO. This verification process is outside the scope of this guide. :::
First you will need to download the SAML metadata file from Amazon Business. This file will be imported into authentik to configure the SAML provider.
https://www.amazon.com/ab/sso/setup/edit/select-idp; your domain may use a different TLD such as .de or .co.uk).Amazon_SP_Metadata.xml file from the bottom of the Amazon Business SSO configuration page.To support the integration of Amazon Business with authentik, you need to create an application/provider pair in authentik.
Amazon_SP_Metadata.xml file that you previously downloaded.authentik default SAML Mapping: Name and authentik default SAML Mapping: Email.https://www.amazon.com/ab/sso/setup/edit/select-idp; your domain may use a different TLD such as .de or .co.uk).authentik).Buyer unless you specify custom roles).metadata.xml) that you downloaded.http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name for the full name and http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress for the email).To confirm that authentik is properly configured with Amazon Business, log out of Amazon Business. Then, on the Amazon login page, enter an email address that belongs to a domain with SSO configured, and click Next. You should be redirected to authentik to log in, and, if successful, be redirected to the Amazon Business portal.