Authentication
Provider-managed login
End-user authentication happens on `sso.gov.mn`. This host only prepares the request, receives the callback, and continues the backend service flow.
Ticket.mn
This endpoint is the public entrypoint for our `sso.gov.mn` integration. The service is configured on a VPN-connected host and handles the provider callback flow securely on behalf of Ticket.mn applications.
Authentication
End-user authentication happens on `sso.gov.mn`. This host only prepares the request, receives the callback, and continues the backend service flow.
Network path
The backend runs on a host with active XYP VPN connectivity so protected downstream service calls can complete after successful authorization.
Operation
This host is kept narrowly scoped to the authentication and callback path required for the integration.