Developer Programs

Learn

Docs

Rollout Considerations

Unified Identity Service > Rollout Considerations

The high-level process for enabling a single financial institution to use Unified Identity Service for a product includes:

Steps and configurations completed by the integrating product development team

  • Determine your enrollment and login redirect URLs before configuration begins — both external application creation and the Jack Henry support case need them. They can be updated on the external application later if they change.
  • Determine which UIS scopes you need for Admin API calls — https://jackhenry.com/uis/uis.enrollment is required for every integration, and https://jackhenry.com/uis/users.read is needed only if you’ll look up UIS user details.
  • Provide the above details to your financial institution contact, since most product teams won’t have direct access to Banno People, Users & Groups, or Jack Henry’s support case system to complete these steps themselves.
  • Implement the flows described in New User Enrollment once credentials are provided. Note that testing against a real institution also requires Jack Henry to have completed institution enablement and product registration — a missing or unregistered product returns an “Invalid client ID” error from enrollment/start.

Steps and configurations completed by the financial institution

Field-level detail for both applications — the exact settings to choose and why — is on the Configuration page.

  • Create a consumer external application (Banno Admin > People > Settings > External Applications) for the product’s Authorization Code flow, using the redirect URLs the product provides. See Configuration.
  • Create a Jack Henry Identity service account external application (Banno Admin > Users & Groups > External Applications) for the product’s Admin API calls, with the required UIS scopes.
  • Share the resulting client IDs with the product’s development team, along with the client secret for the consumer external application. The service account application doesn’t use a client secret — the product supplies its own public key (PEM or JWKS URL) for that one.
  • Open a support case with Jack Henry to enable UIS for the institution and register the product, providing:
    • Institution ID
    • Client ID (from the consumer external application)
    • Product name (as it should appear in the Identity app)
    • Enrollment redirect URL
    • Login redirect URL

Steps and configurations completed by Jack Henry

  • Enable UIS for the institution.
  • Register the product so it displays correctly in the Identity app and redirects work as expected.

These steps require a support case — they are not available as self-service actions in Banno People or Users & Groups. They can’t be completed until the financial institution has created the external application(s) and provided the details above.

Recommendations

  • Start this configuration early. Both the financial institution’s external application setup and the Jack Henry support case can take time, and both need your redirect URLs in hand before they can be completed.
  • It’s a good idea to create specific instructions for your financial institution contacts to follow, including your product-specific values (redirect URLs, scopes, desired product name), so they aren’t starting from our generic examples.

Have a Question?

Did this page help you?

Last updated Wed Sep 2 2026