# Is there a way we can access the external\_id from SSO record of another user?

**URL:** <https://meta.discourse.org/t/is-there-a-way-we-can-access-the-external-id-from-sso-record-of-another-user/300989>\
**Category:** SSO\
**Created:** [March 26, 2024, 12:43pm UTC](https://meta.discourse.org/t/is-there-a-way-we-can-access-the-external-id-from-sso-record-of-another-user/300989 "2024-03-26T12:43:40Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![junbetterway](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/junbetterway/32/372464_2.png) [@junbetterway](https://meta.discourse.org/u/junbetterway)\
**Post date:** [March 26, 2024, 12:43pm UTC](https://meta.discourse.org/t/is-there-a-way-we-can-access-the-external-id-from-sso-record-of-another-user/300989/1 "2024-03-26T12:43:40Z")

</div>

We have no issue accessing the `external_id` from SSO record of the current logged-in user using below approach:

`api.getCurrentUser().external_id`

However, we have some buttons/links when the current logged-in user is viewing another one’s profile summary ( **e.g.,** Person X). This `external_id` is the primary identifier used in our website which we will be using for some redirects and actions from our website. Using the admin user API works but obviously not for non-admin user accounts.

Is this possible and how?

---

<div class="post-metadata">

**Author:** ![pfaffman](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/pfaffman/32/120154_2.png) [@pfaffman](https://meta.discourse.org/u/pfaffman)\
**Post date:** [March 26, 2024, 5:40pm UTC](https://meta.discourse.org/t/is-there-a-way-we-can-access-the-external-id-from-sso-record-of-another-user/300989/2 "2024-03-26T17:40:16Z")

</div>

I think you want a plugin that adds the external\_id to the user serializer.

Something like:

```plaintext
  add_to_serializer(:user, :external_id) do
     object.external_id
  end

```

---

<div class="post-metadata">

**Author:** ![simon](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/simon/32/339122_2.png) [@simon](https://meta.discourse.org/u/simon)\
**Post date:** [March 26, 2024, 8:23pm UTC](https://meta.discourse.org/t/is-there-a-way-we-can-access-the-external-id-from-sso-record-of-another-user/300989/3 "2024-03-26T20:23:15Z")

</div>

I think it would be something like:

```ruby
# in the plugin's after_initialize block
after_initialize do

# Edit: probably also check to make sure that `SiteSetting.enable_discourse_connect` returns `true`
  add_to_serializer(:user, :external_id) {object&.single_sign_on_record&.external_id}
end

```

The `external_id` is a property of the `single_sign_on_record` not the `user`. I remember this because I had something to do with:

> <https://github.com/discourse/discourse/blob/main/app/serializers/current_user_serializer.rb#L275-L281>

---

<div class="post-metadata">

**Author:** ![junbetterway](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/junbetterway/32/372464_2.png) [@junbetterway](https://meta.discourse.org/u/junbetterway)\
**Post date:** [March 27, 2024, 2:05pm UTC](https://meta.discourse.org/t/is-there-a-way-we-can-access-the-external-id-from-sso-record-of-another-user/300989/4 "2024-03-27T14:05:40Z")

</div>

Thanks everyone for the inputs, we ended up doing this via custom user fields which gets synced from our application during login.

---

<div class="post-metadata">

**Author:** ![system](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/system/32/443519_2.png) [@system](https://meta.discourse.org/u/system)\
**Post date:** [April 26, 2024, 2:06pm UTC](https://meta.discourse.org/t/is-there-a-way-we-can-access-the-external-id-from-sso-record-of-another-user/300989/5 "2024-04-26T14:06:01Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
