---
sourceDocument: Xanadu Customer Service Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/xanadu/customer-service-management

 Release :

    - xanadu

ft:locale :

    - en-US

ft:publication_title :

    - Xanadu Customer Service Management

ft:clusterId :

    - csm

bundleId :

    - csm

workflow :

    - Customer and Industry


---

# Create an identity provider (IdP) for Engagement Messenger

# Create an identity provider (IdP) for Engagement Messenger {#ariaid-title1}

* Release version: Xanadu
* 
* Updated August 1, 2024
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Create an IdP for your Engagement Messenger so that you can enable
customer authentication. You can create an IdP for either the OpenID Connect (OIDC) or
Security Assertion Markup Language (SAML) authentication type.

## Before you begin

Role required: admin

## About this task

If you previously configured an IdP, you can ignore this task and reuse the existing IdP.  
Note:  
If you have configured multiple IdPs on your instance and want to select a specific IdP for your Engagement Messenger module, do the following:

* [Enable Engagement Messenger on a website when third-party application cookies are blocked](https://servicenow-prod.fluidtopics.net/t42RqARp~0JpgWAUpKgecg "Configure a custom URL for the ServiceNow instance that helps prevent web browsers from blocking Engagement Messenger when cross-origin iframes and third-party cookies are blocked.")
* [Custom URL with Identity Provider](https://www.servicenow.com/docs/access?context=custom-url-with-multiple-identity-providers&version=xanadu&pubname=xanadu-platform-security&ft:locale=en-US)
* If you have multiple IdPs on your instance:
  * In case of OIDC authentication type, the generated ID token should contain the client ID of a IdP record against which authentication is required.
  * In case of SAML authentication type, set the particular IDP record as Auto-redirect IdP.

  {#create-identity-providers-for-engagement-messenger__ul_ery_3rb_3cc}  
  Note:  
  For more information, see [Setting up auto login and logout for Engagement Messenger](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1560205).
{#create-identity-providers-for-engagement-messenger__ul_gbz_hrf_1xb}

## Procedure

1. Navigate to AllEngagement MessengerAdministrationIdentity Providers.
2. Select New.
3. Select either OpenID Connect or SAML.
   * If you select OpenID Connect, follow the procedure in [Create an OpenID
     Connect (OIDC) configuration for Single Sign-On (SSO)](https://www.servicenow.com/docs/access?context=create-OIDC-configuration-SSO&version=xanadu&pubname=xanadu-platform-security&ft:locale=en-US).
   * If you select SAML, follow the procedure from step 3 in [Create and update
     identity providers](https://www.servicenow.com/docs/access?context=t_CreateUpdateIdentityProvider&version=xanadu&pubname=xanadu-platform-security&ft:locale=en-US).
   {#create-identity-providers-for-engagement-messenger__choices_rdn_w25_f4b}

## What to do next

* When customers sign in to your website where the Engagement Messenger module is deployed, they must also be authenticated within the messenger. User authentication is done by using the same IdP that authenticated the customer's login into your website.

  You must verify that the customers of your website are also added in your OIDC or SAML authentication provider for the ServiceNow instance.
* Enable cross-domain requests between Engagement Messenger and your website. For more information, see [Configure a CORS rule for Engagement Messenger](https://servicenow-prod.fluidtopics.net/zITMe1zR2OkRvp~lKgMNvA "Configure a cross-origin resource sharing (CORS) rule to enable cross-domain requests between Engagement Messenger and your website where you want to deploy the messenger.").
{#create-identity-providers-for-engagement-messenger__ul_gfs_3k5_f4b}
**Related topics**   

* [How to set up OIDC provider on ServiceNow instance](https://support.servicenow.com/kb_view.do?sysparm_article=KB0778342)

*[\>]: and then


