Skip to main content

Configure Single Sign-On (SSO)

This guide explains how to configure Single Sign-On (SSO) for your organization using OIDC or SAML.

With SSO enabled, members of your organization authenticate through your corporate Identity Provider (IdP) instead of managing separate login credentials on the platform.

Which protocol should I choose?​

ProtocolWhen to use
OIDCYour IdP exposes OIDC / OAuth 2.0 endpoints; you want one-click setup via an Issuer URL; you prefer a lighter JSON-based integration.
SAMLYour IdP only supports SAML; you need IdP-initiated SSO; you already run a SAML-based authentication stack.

Configuration process​

Go to Platform Settings > SSO, then complete the three steps below.

Step 1: Select protocol and fill in configuration​

  1. Go to Platform Settings > SSO and choose OIDC or SAML depending on your IdP.
  2. Fill in the protocol-specific information below. Provide these details to your IdP.
FieldDescription
ProtocolSelect OIDC.
Issuer URLThe IdP's issuer URL, used for endpoint auto-discovery.
Client IDThe client ID issued by your IdP.
Client SecretThe client secret issued by your IdP (masked).
Redirect URIGenerated by the platform; add it to your IdP's allowed redirect URIs.

On the IdP side, register an OAuth 2.0 / OIDC application and add the generated Redirect URI to its allowed redirect URIs. Copy the issued Client ID and Client Secret back into the platform.


OIDC SSO configuration

Step 2: Configure attribute mapping​

Attribute Mapping maps the fields in your IdP assertion to the user's email, name, and unique subject.

FieldDescription
Email AttributeThe attribute holding the user's email. Default: email.
Name AttributeThe attribute holding the user's display name. Default: name.
Subject AttributeThe unique, stable identifier for the user. OIDC default: sub; SAML default: NameId.

Step 3: Test the connection and activate​

  1. After you complete the configuration above, click Test Connection to verify the connection to your IdP.
  2. If the test passes, click Activate to enable SSO for your organization.
  3. After activation, members can sign in to the User Console through your IdP using SSO.
  4. To stop using SSO at any time, return to the configuration page and click Deactivate.

SSO Activation

User Console login

User Console SSO login

After activation, members sign in to the User Console through your IdP using SSO.

Emergency Access

Before you activate SSO, keep at least one emergency admin account that can sign in without SSO. This account lets you access settings if your IdP loses connectivity.

Next Step​

Next, configure User Control for administrator access, or Theme for tenant branding.