# What is SSO (Single Sign-On)?

Basically, **<mark> Single Sign-On (SSO) is an authentication </mark>** scheme. It allows a user to log in to **<mark>different systems using a single ID.</mark>**

The diagram below illustrates how SSO works.

Step 1: A user visits Gmail, or any email service. Gmail finds the user is not logged in and **<mark>so redirects them to the SSO authentication server</mark>**, which also finds the user is not logged in. As a result, the user is **<mark>redirected to the SSO login page</mark>**, where they enter their login credentials.

Steps 2-3: **<mark>The SSO authentication server validates the credentials, creates the global session</mark>** for the user, and creates a token.

Steps 4-7: **<mark> Gmail validates the token in the SSO authentication server. </mark>** The authentication server registers the Gmail system, and **<mark>returns “valid.” Gmail returns the protected resource to the user.</mark>**

Step 8: From Gmail, the user **<mark> navigates to another Google-owned website, for example, YouTube.</mark>**

Steps 9-10: YouTube finds the user is not logged in, and then requests authentication. **<mark> The SSO authentication server finds the user is already logged in and returns the token.</mark>**

Step 11-14: **<mark>YouTube validates the token in the SSO authentication server. </mark>** The authentication server registers the YouTube system, **<mark>and returns “valid.” </mark>** YouTube returns the protected resource to the user.

<mark>The process is complete</mark> and the user gets back access to their account.

---

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1703326020264/a25a14a3-9ad1-4dbc-8860-187f0864dbe6.jpeg align="center")
