# Single Sign-On Authentication

> Accept Google, Azure AD and AWS Cognito tokens in API Maker and map each user to your groups, or write your own token provider.

Source: https://docs.apimaker.dev/v1/docs/features/single-sign-on-authentication.html

- Your app signs users in with Google, Azure AD or AWS Cognito and sends the token it gets to API Maker.
- API Maker checks the token with the keys of the provider, finds the user in a table of yours, and runs the call with the groups of that user.
- Send the token in its header: `x-google-authorization`, `x-azure-authorization` or `x-aws-authorization`.
- Read the opened token in your code from `g.req.auth.authGoogle`, `g.req.auth.authAzure` or `g.req.auth.authAWS`.
- For any other system, write a custom provider: a token generator and a token validator in TypeScript. Send its token in `x-custom-authorization` and read the result in `g.req.auth.authCustom`.
- Learn more [Google](/v1/docs/authorization/Google.html), [Azure AD](/v1/docs/authorization/Azure.html), [AWS Cognito](/v1/docs/authorization/AWS.html) and [custom auth provider](/v1/examples/req/auth/authCustom.html).
