Developer Programs

Learn

Docs

Configuration

Unified Identity Service > Integration Tips > Configuration

Unified Identity Service integrations need two separate external applications. Unless your team is part of the financial institution itself, you likely won’t create these directly — most integrating product teams don’t have access to Banno People or Users & Groups. Your financial institution contact will need to create these on your behalf. See Rollout Considerations for the full breakdown of who does what.

Consumer External Application (Authorization Code Flow)

This is the client used in the Authorization Code flow described in New User Enrollment — its clientId is passed to the enrollment/start API and used in the /oidc/auth redirect.

This is created in Banno Admin > People > Settings > External Applications:

  • Name: choose “Custom application” from the dropdown, then provide your own branded name.
  • Partner: identify your product (e.g., your company name).
  • Client type: Confidential
  • Require PKCE: we recommend enabling this, consistent with our general PKCE guidance, even though it isn’t required for a Confidential client.
  • User consent required: see Consumer API configuration guidance for when to require consent.
  • Redirect URIs: add both your enrollment and login redirect URLs. Each is matched by exact string — matching is case-sensitive and path-inclusive, and wildcards aren’t allowed — so the values registered here must match what your product sends, character for character.

Once created, your financial institution contact will need to share the resulting Client ID (and secret) with you.

Service Account External Application (Client Credentials Flow)

Your product will use this to call the UIS Admin API. Every UIS integration needs this, since the enrollment/start call is a required step in New User Enrollment. This is a Jack Henry Identity Service Account application — follow the Jack Henry Identity configuration guide for setup steps, and request these UIS scopes:

  • https://jackhenry.com/uis/uis.enrollment — required, used for enrollment/start
  • https://jackhenry.com/uis/users.read — only if your product also needs to look up UIS user details

Enabling UIS for an Institution

Creating both external applications isn’t enough on its own — UIS must also be enabled for the institution, and your product registered with Jack Henry, before you can go live. This isn’t self-service. See Rollout Considerations for what the financial institution will need to include when opening a support case.


Have a Question?

Did this page help you?

Last updated Wed Sep 2 2026