ExtensisHR acts as the SAML 2.0 identity provider for Alight Solutions.
Employees reach Alight through an IdP-initiated, HTTP-POST single
sign-on carrying their employee id as the SAML subject and the
Alight-assigned clientId attribute.
Used by the ESS web portal, which passes a PrismHR TSSO token.
/saml/login?peo_id=593*C&key=<tsso token>
Used by the HRCloud app. ExtensisAPI stages the record and hands back the key.
/saml/InitiateSingleSignOnMobile?key=<guid>
Both entry points accept an optional pageCd (appended to the
configured RelayState) or a full relay URL. Either must fall
under one of the prefixes in AlightRelayStateAllowedPrefixes.