Skip to main content

Integrating Single Sign-On with Disqus Boards

SSO implementation steps for Disqus Boards

Written by Ryan

This article assumes that you have already set up an SSO application with Disqus. If you haven’t yet, please start with this article: Integrating Single Sign-On. This article only covers what is different when you embed SSO with Boards.

Access to Single Sign-On (SSO) is currently available as an add-on for users with a Business level subscription.

Single Sign-On lets visitors use their site account with Disqus Boards without signing in to Disqus separately. Boards uses the same SSO application, remote domain, and HMAC payload as Disqus Comments. You do not create a second SSO user store.

What stays the same

  • Remote domain (one per Organization)

  • API application: Domains, SSO Domain, OAuth permissions

  • Payload: Base64 JSON + HMAC-SHA1 + Unix timestamp, space-separated

  • Required user fields: id, username, email

  • Optional: avatar, url, profile_url

  • Payloads expire after two hours

  • Logout payload: signed empty JSON object {}

  • User deletion: same overwrite or deleteSSOUser flow as comments

Note: For local testing of Boards, Disqus Staff can help add every Boards page origin to the API application Domains list (localhost / 127.0.0.1 for local testing).

What is different

Comments

Boards

disqus_config

disqus_boards_config

embed.js

<https://<shortname>>.disqus.com/boards.js

DISQUS.reset({ reload: true, config: … })

DISQUS_BOARDS.authenticate()

Comments forum

Dedicated boards-<shortname> forum in the same Organization

SSO_AUTH_ONLY on the comments forum

SSO_AUTH_ONLY on the Boards forum

Boards is usually embedded on an entire page. Comment threads inside a discussion are mounted by Boards using the shortname boards-<shortname>. Set this.sso on disqus_boards_config and Boards will copy page.api_key, page.remote_auth_s3, and this.sso into comment embeds generated in Boards discussions, including when the visitor is logged out (api_key plus sso.url is enough for the publisher login row). There is no need to add a second disqus_config SSO block on those pages, as our Boards code takes care of that for you.

Boards SSO Script

Load this before boards.js. Generate remote_auth_s3 on your server. Never put your Disqus secret key in page JavaScript.

<div id="disqus-boards-host"></div>
<script>
window.disqus_boards_config = function () {
this.page.api_key = 'YOUR_PUBLIC_API_KEY';
this.page.remote_auth_s3 = 'SIGNED_MESSAGE SIGNATURE TIMESTAMP';
};
</script>
<script>
(function () {
if (document.getElementById('disqus_boards_script')) return;
var d = document, s = d.createElement('script');
s.id = 'disqus_boards_script';
s.src = 'https://YOUR_SHORTNAME.disqus.com/boards.js';
(d.head || d.body).appendChild(s);
})();
</script>

Use the public key of the API application that owns your SSO domain. That application must be in the same Organization as the Boards forum.

After login or logout

  1. Put a freshly signed remote_auth_s3 on that object (keep api_key).

  2. Call DISQUS_BOARDS.authenticate().

window.disqus_boards_config.page.api_key = 'YOUR_PUBLIC_API_KEY';
window.disqus_boards_config.page.remote_auth_s3 = newPayload;
DISQUS_BOARDS.authenticate();

That is the Boards equivalent of DISQUS.reset({ reload: true, config: function () { … } }).

Logging out of SSO is a signed empty payload, not blank fields and not omitting headers:

window.disqus_boards_config.page.api_key = 'YOUR_PUBLIC_API_KEY';
window.disqus_boards_config.page.remote_auth_s3 =
'BASE64({}) SIGNATURE TIMESTAMP'; // no id / username
DISQUS_BOARDS.authenticate();

Publisher login and logout links (this.sso)

Set this.sso when you want Boards to show your site login next to (or instead of) Disqus login.
​

SSO-lite (publisher login + Disqus login)

window.disqus_boards_config = function () {
this.page.api_key = 'YOUR_PUBLIC_API_KEY';
this.page.remote_auth_s3 = 'SIGNED_MESSAGE SIGNATURE TIMESTAMP';
this.sso = {
name: 'Sign in with this site',
url: 'https://yoursite.com/sso/login/',
logout: 'https://yoursite.com/sso/logout/',
width: 800,
height: 400,
// icon: 'https://yoursite.com/favicon.png',
// useRedirect: true,
};
};
  • name — Label on the publisher login row.

  • icon — Small logo in the same slot as the Disqus mark (recommended).

  • button — Full-row image. Prefer icon plus name so the row matches Disqus login. A missing or broken icon falls back to a generic glyph (a 404 icon URL can show as a broken image).

  • url — Your login page. Default: popup. The popup should close itself when login finishes; Boards then reloads the host page so you can inject the new remote_auth_s3.

  • useRedirect — If true, Boards navigates this tab to url and appends return_url (the current page). After login, send the user back to return_url.

  • logout — Your logout page. Boards navigates here exactly as written. It does not add return_url. Your logout page should clear the site session and send the user back (for example via document.referrer, restricted to your origin). If logout is missing or invalid, Boards falls back to Disqus logout.

  • width / height — Popup size only. Unused in redirect mode.

Do not rely on the comments 143×32 “SSO login button” PSD for Boards. Boards is a text row with a 22px glyph, not that chip.

SSO-only (SSO_AUTH_ONLY)

Ask your Disqus account manager to enable SSO Auth required (SSO_AUTH_ONLY) on boards-<shortname>. That is the forum for the Boards shell and for comment threads inside discussions, so one setting covers both (the shell via Boards; the embed via Disqus).

When it is enabled:

  • Disqus login is hidden.

  • If this.sso.url is set, visitors can open New Discussion, write a draft, and are asked to sign in with your site when they publish. The draft survives the reload that finishes popup or redirect login.

  • If this.sso.url is missing, Boards hides the anonymous auth card and New Discussion (same idea as comments hiding the comment box).

this.sso = {
url: 'https://yoursite.com/sso/login/',
logout: 'https://yoursite.com/sso/logout/',
useRedirect: true,
};

Examples

Did this answer your question?