New Community Ranking System
Our Community ranking system has recently been updated. You may notice changes in user rankings and receive system messages or notifications. If you have questions about how the new ranking works, please refer to the announcement post for more details (click here).
Experior & Remote Viewer – OpenID Connect (OIDC) Login Guide
Digital Twin
This knowledge base is addressing usage of software Experior, Machine Expert Twin and future Automation Expert Twin. These softwares are used to create smaller instances of digital twins for use in industrial automation, warehouse management, design & engineering with more..
Search in
Improve your search experience:
Exact phrase→Use quotes " "(e.g., "error 404")
Wildcard→Use * for partial words(e.g., build*, *tion)
AND / OR→Combine keywords(e.g., login AND error, login OR sign‑in)
Keep it short→Use 2–3 relevant words, not full sentences
Filters→Narrow results by section(Knowledge Base, Users, Products)
Send a co-worker an invite to the portal.Just enter their email address and we'll connect them to register. After joining, they will belong to the same company.
You have entered an invalid email address. Please re-enter the email address.
This co-worker has already been invited to the Exchange portal. Please invite another co-worker.
Please enter email address
Send InviteCancel
Invitation Sent
Your invitation was sent.Thanks for sharing Exchange with your co-worker.
This document explains how to enable OpenID Connect (OIDC) authentication for Experior and the Experior Remote Viewer. Once configured, users can authenticate via an external Identity Provider (IdP) instead of using local credentials.
This setup supports standard OIDC-compatible identity providers (e.g., Azure AD, Keycloak, Auth0, Okta, or similar platforms).
Prerequisites
Before starting, ensure the following:
Experior is installed and runnable
Experior Remote Viewer is available
Access to an Identity Provider (IdP) that supports OpenID Connect
Ability to register a client/application in the IdP
1. Experior Configuration
Runtime Requirements
Experior must be started using one of the following modes:
-graphicsserver
-headless
These modes enable the web interface and API required for authentication.
Web API Configuration
Update the WebApiSettings.json file to include identity provider settings.
In this scenario, Experior will query the external API to retrieve the required IdP configuration.
Other Relevant Settings
Ensure the following sections are configured as needed:
WebUi.Enabled = true
CorsConfiguration.AllowAll = true (or restrict appropriately for production)
CertificateConfiguration.AllowInsecureCertificate should be false in production
2. Identity Provider Setup
Your Identity Provider must be configured with a client application for Experior Remote Viewer.
Required Configuration
Create a client with the following characteristics:
Client ID: experior-remote-viewer (or match your configuration)
Protocol: OpenID Connect
Redirect URI: Must match RedirectUri in WebApiSettings.json
Scopes: At minimum openid
Optional but recommended:
Enable refresh tokens
Configure logout redirect URI
Add additional scopes such as profile or email
Supported Identity Providers
Any OIDC-compliant provider can be used, for example:
Azure Active Directory
Keycloak
Auth0
Okta
3. Remote Viewer Setup
The Remote Viewer uses the configured Identity Provider via Experior's API.
Ensure:
Remote Viewer can reach the Experior Web API
Redirect URI configured in the IdP matches the viewer callback endpoint
Network configuration allows communication between viewer, Experior, and the IdP
4. Login Flow
The authentication flow works as follows:
User opens the Remote Viewer
User is redirected to the Identity Provider login page
User authenticates with the IdP
IdP redirects back to the Remote Viewer using the configured callback URL
Experior validates the token
Access is granted
5. Best Practices
Always use HTTPS in production environments
Do not allow insecure certificates outside of development
Restrict CORS settings to known origins
Keep client secrets and configuration secure
Align redirect URIs exactly between configuration and IdP
Summary
By configuring Experior with an OpenID Connect-compatible Identity Provider, you enable secure, centralized authentication for both Experior and the Remote Viewer. This allows integration with enterprise identity systems and improves security and user management.