Help
  • Explore Community
  • Get Started
  • Ask the Community
  • How-To & Best Practices
  • Contact Support
Notifications
Login / Register
Schneider Electric
Community
Community
Notifications
close
  • Categories
  • Forums
  • Knowledge Center
  • Blogs
  • Ideas
  • Events & Webinars
Help
Help
  • Explore Community
  • Get Started
  • Ask the Community
  • How-To & Best Practices
  • Contact Support
Login / Register

Contact Support

Close

Ask our Experts

Have a question related to our products, solutions or services? Get quick support on community Forums

Email Us

For Community platform-related support, please email us

New Community Ranking System
Our Community ranking system has recently been updated. You may notice changes in user rankings and receive system messages or notifications. If you have questions about how the new ranking works, please refer to the announcement post for more details (click here).

Experior & Remote Viewer – OpenID Connect (OIDC) Login Guide

Digital Twin

This knowledge base is addressing usage of software Experior, Machine Expert Twin and future Automation Expert Twin. These softwares are used to create smaller instances of digital twins for use in industrial automation, warehouse management, design & engineering with more..

Search in

Improve your search experience:

  • Exact phrase → Use quotes " " (e.g., "error 404")
  • Wildcard → Use * for partial words (e.g., build*, *tion)
  • AND / OR → Combine keywords (e.g., login AND error, login OR sign‑in)
  • Keep it short → Use 2–3 relevant words , not full sentences
  • Filters → Narrow results by section (Knowledge Base, Users, Products)
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Select a Country

Please select a country to continue with beta search.

  • Home
  • Schneider Electric Community
  • Knowledge Center
  • Digital Twin
  • Experior & Remote Viewer – OpenID Connect (OIDC) Login Guide
Options
  • Bookmark
  • Subscribe
  • Email to a Friend
  • Printer Friendly Page
  • Report Inappropriate Content
Invite a Co-worker
Send a co-worker an invite to the portal.Just enter their email address and we'll connect them to register. After joining, they will belong to the same company.
You have entered an invalid email address. Please re-enter the email address.
This co-worker has already been invited to the Exchange portal. Please invite another co-worker.
Please enter email address
Send Invite Cancel
Invitation Sent
Your invitation was sent.Thanks for sharing Exchange with your co-worker.
Send New Invite Close

Related Forums

  • Intelligent Devices Forum

Previous Next
Contributors
  • Kasper.Vestrup
    Kasper.Vestrup

Invite a Colleague

Found this content useful? Share it with a Colleague!

Invite a Colleague Invite
Back to Digital Twin
Start a Topic
Options
  • Bookmark
  • Subscribe
  • Email to a Friend
  • Printer Friendly Page
  • Report Inappropriate Content
0 Likes
353 Views

Link copied. Please paste this link to share this article on your social media post.

Trying to translate this page to your language?
Select your language from the translate dropdown in the upper right. arrow
Translate to: English
  • (Français) French
  • (Deutsche) German
  • (Italiano) Italian
  • (Português) Portuguese
  • (Русский) Russian
  • (Español) Spanish

Experior & Remote Viewer – OpenID Connect (OIDC) Login Guide

Kasper.Vestrup Explorer
‎2026-05-26 02:06 AM

on ‎2026-05-26 02:06 AM

Overview

This document explains how to enable OpenID Connect (OIDC) authentication for Experior and the Experior Remote Viewer. Once configured, users can authenticate via an external Identity Provider (IdP) instead of using local credentials.

This setup supports standard OIDC-compatible identity providers (e.g., Azure AD, Keycloak, Auth0, Okta, or similar platforms).

 

Prerequisites

Before starting, ensure the following:

  • Experior is installed and runnable
  • Experior Remote Viewer is available
  • Access to an Identity Provider (IdP) that supports OpenID Connect
  • Ability to register a client/application in the IdP

 

1. Experior Configuration

Runtime Requirements

Experior must be started using one of the following modes:

  • -graphicsserver
  • -headless

These modes enable the web interface and API required for authentication.

 

Web API Configuration

Update the WebApiSettings.json file to include identity provider settings.

Option A – Direct OIDC Configuration

Provide explicit configuration values:

1     "IdentityProvider": {
2       "Authority": "https://<idp-domain>/",
3       "Issuer": "https://<idp-domain>/",
4       "Audience": "account",
5       "ClientId": "experior-remote-viewer",
6       "UserIdField": "",
7       "RedirectUri": "http://127.0.0.1:8080/callback",
8       "EndSessionRedirectUri": "http://localhost:8080/",
9       "AuthorizationScope": "openid",
10       "Prompt": "login"
11     }

 

Option B – Dynamic Configuration via External API

Alternatively, configuration can be retrieved from an external service:

1     "ExternalApi": {
2       "BaseUrl": "http://localhost:5050/api",
3       "IdpEndpoint": "/idp"
4     },
5     "IdentityProvider": {
6       "Authority": "",
7       "Issuer": "",
8       "Audience": "",
9       "ClientId": "",
10       "UserIdField": "",
11       "RedirectUri": "",
12       "EndSessionRedirectUri": "",
13       "AuthorizationScope": "",
14       "Prompt": "login"
15     }

In this scenario, Experior will query the external API to retrieve the required IdP configuration.

Other Relevant Settings

Ensure the following sections are configured as needed:

  • WebUi.Enabled = true
  • CorsConfiguration.AllowAll = true (or restrict appropriately for production)
  • CertificateConfiguration.AllowInsecureCertificate should be false in production

 

2. Identity Provider Setup

Your Identity Provider must be configured with a client application for Experior Remote Viewer.

Required Configuration

Create a client with the following characteristics:

  • Client ID: experior-remote-viewer (or match your configuration)
  • Protocol: OpenID Connect
  • Redirect URI: Must match RedirectUri in WebApiSettings.json
  • Scopes: At minimum openid

Optional but recommended:

  • Enable refresh tokens
  • Configure logout redirect URI
  • Add additional scopes such as profile or email

Supported Identity Providers

Any OIDC-compliant provider can be used, for example:

  • Azure Active Directory
  • Keycloak
  • Auth0
  • Okta

 

3. Remote Viewer Setup

The Remote Viewer uses the configured Identity Provider via Experior's API.

Ensure:

  • Remote Viewer can reach the Experior Web API
  • Redirect URI configured in the IdP matches the viewer callback endpoint
  • Network configuration allows communication between viewer, Experior, and the IdP

 

4. Login Flow

The authentication flow works as follows:

  1. User opens the Remote Viewer
  2. User is redirected to the Identity Provider login page
  3. User authenticates with the IdP
  4. IdP redirects back to the Remote Viewer using the configured callback URL
  5. Experior validates the token
  6. Access is granted

 

5. Best Practices

  • Always use HTTPS in production environments
  • Do not allow insecure certificates outside of development
  • Restrict CORS settings to known origins
  • Keep client secrets and configuration secure
  • Align redirect URIs exactly between configuration and IdP

 

Summary

By configuring Experior with an OpenID Connect-compatible Identity Provider, you enable secure, centralized authentication for both Experior and the Remote Viewer. This allows integration with enterprise identity systems and improves security and user management.

Labels (1)
Labels:
  • Remote Viewer

Link copied. Please paste this link to share this article on your social media post.

You’ve reached the end of your document

WHAT’S NEXT?

Ask our Experts

Didn't find what you are looking for? Ask our experts!

My Dashboard

Check out the new Feeds and activities that are relevant to you.

To The Top!

Forums

  • APC UPS Data Center Backup Solutions
  • EcoStruxure IT
  • EcoStruxure Geo SCADA Expert
  • Metering & Power Quality
  • Schneider Electric Wiser

Knowledge Center

Events & webinars

Ideas

Blogs

Get Started

  • Ask the Community
  • Community Guidelines
  • Community User Guide
  • How-To & Best Practice
  • Experts Leaderboard
  • Contact Support

    Ask our Experts

    Have a question related to our products, solutions or services? Get quick support on community Forums

    Email Us

    For Community platform-related support, please email us

Subscribing is a smart move!
You can subscribe to this board after you log in or create your free account.
Forum-Icon

Create your free account or log in to subscribe to the board - and gain access to more than 10,000+ support articles along with insights from experts and peers.

Register today for FREE

Register Now

Already have an account? Login

Terms & Conditions Privacy Notice Change your Cookie Settings © 2026 Schneider Electric

Welcome!

Welcome to your new personalized space.

of

Explore