Skip to main content

Migration action required: callback URLs and allowlist updates

Audience: Admins and IT administrators responsible for authentication migration

Overview

Legora is moving to a new authentication protocol so each user has one identity across Legora, no matter which region or organization they work in. As part of this change, your organization will use a dedicated login URL and updated authentication routes.

To prepare for rollout, admins and IT administrators need to make the following updates:

  1. Add the new callback URLs in your identity provider and active integration settings.

  2. Whitelist the required domains on your network.

Keep all existing URLs and settings in place. These updates should be added alongside your current configuration.


Add callback URLs

Identity provider callback URLs

If your organization uses SSO, add the following URLs as allowed callback URIs in your identity provider configuration:

  1. https://sso.legora.com/api/oauth/saml

  2. https://sso.legora.com/api/oauth/oidc

Important note: All updates should be made in addition to your existing configuration. Do not remove any existing URLs or settings at any point during this process.

Where to add them depends on your provider:

  1. Okta: Add both URLs to the Sign-in redirect URIs in the Legora application settings.

  2. Microsoft Entra ID: Add both URLs to the Redirect URIs in the Legora app registration. Refer to Enabling the Entra ID integration.

  3. Other identity providers: Add both URLs as allowed callback URIs following your provider’s documentation.

Integration callback URLs

For each active integration, add the relevant redirect URI in that integration’s admin settings:

Integration

URL/URI to add

Where to add it

iManage (on-premises)

https://app.legora.com/imanage

Add the link in your iManage configuration as an allowed callback URL. Refer to our support page on Enabling iManage integration - On-Prem setup guide.

SharePoint

https://app.legora.com/sharepoint

Add the link as a registered redirect URI in SharePoint admin. Refer to our support page on Enabling the Sharepoint integration guide.

Google Drive

https://app.legora.com/google-drive

Add the link as a redirect URI in Google Workspace admin. Refer to our support page for Google drive integration overview.

iManage Cloud

No action needed

Legora handles this automatically.


Allowlist domains

Allowlist the following domains on your network, for both inbound and outbound traffic as applicable to your network setup:

  1. Add your organization’s new dedicated domain to your network allowlist. You can find this domain at the top of Settings > Authentication migration. For instructions, see Legora network and domain requirements.

  2. https://auth.legora.com


Portal and mobile app

Portal

If your organization invites another Legora customer to your Portal, both organizations must be on the new authentication protocol before the invitation can work. Portal invitations to clients who do not use Legora are not affected.

Mobile app

Mobile app access remains unchanged. Users may need to sign in again after migration.

Word and Outlook Add-in

After your organization completes migration to Legora’s new authentication protocol, the existing add-ins will stop working and will need to be reinstalled. Going forward there will be a single Word add-in and a single Outlook add-in, both available in Microsoft AppSource.

When you reinstall the Word or Outlook add-in, any thread history created in the existing add-in will not carry over. This history cannot be recovered. If there is anything you may need to reference, save it somewhere before reinstalling.


Review your organization’s dedicated domain

  1. From your name in the sidebar, select Settings > Authentication migration.

  2. Review the dedicated login URL that Legora has pre-populated for your organization.

  3. If you need to change it, make the change before the migration.


Additional help

If you are unsure which updates apply to your organization, contact your Legora representative.

Did this answer your question?