SSO Integrations (SAML)
The platform is able to support Single Sign-On (SSO) integrations through SAML.
SSO Integrations (SAML)
Our platform supports Single Sign-On (SSO) using the SAML (Security Assertion Markup Language) standard. SAML allows users to sign in to the platform using the credentials and identity provider (IdP) managed by their organization, rather than maintaining a separate platform password.
SAML is an open standard commonly used for secure authentication between an organization's Identity Provider (IdP) and an application or Service Provider (SP).
Using SAML means we can support SSO integrations with a wide range of identity providers, including:
- Microsoft Entra ID (formerly Azure Active Directory)
- Okta
- Other SAML-compatible Identity Providers
SSO can be enabled for both web and mobile app logins.
Supported Identity Providers
Microsoft Entra ID
If your organization uses Microsoft 365, you may be using Microsoft Entra ID (formerly Azure Active Directory) as your Identity Provider.
In this case, the SAML application will need to be configured within your Microsoft Entra tenant.
Implementation instructions and the required SAML URLs will be provided by our team during implementation.
Okta
We also support SAML SSO through Okta.
The Okta application will need to be configured using the SAML integration details provided by our team during implementation.
Other SAML-compatible providers
Because SAML is an industry-standard authentication protocol, we may also be able to support other SAML-compatible Identity Providers.
If you use an Identity Provider other than Microsoft Entra ID or Okta, please let your account or onboarding manager know. We can provide the relevant SAML integration details and confirm any provider-specific requirements.
SAML attributes
During authentication, our platform reads specific attributes from the SAML response to identify and provision the user.
The standard attributes are:
|
Attribute |
Required |
Description |
|
FirstName |
Yes |
The user's first name |
|
LastName |
Yes |
The user's last name |
|
|
Yes |
The user's email address |
|
Phone |
Optional |
The user's phone number |
|
Unique User Identifier |
Yes |
A unique identifier used to identify the user |
The exact attribute names or claims may vary depending on your Identity Provider. During implementation, these should be mapped to the corresponding fields expected by our platform.
Custom attributes
If you need additional attributes to be captured through SSO, please inform your account or onboarding manager.
Additional attributes can be reviewed for custom mapping, subject to the requirements of the integration.
Metadata URL
Once your Identity Provider has been configured, we will require your Metadata URL to complete the SAML setup on our side.
The metadata contains information that allows the platform to establish the SAML configuration and trust relationship with your Identity Provider.
Please provide the Metadata URL to your account or onboarding manager once the Identity Provider configuration is complete.
User login vs. user profile synchronization
SAML SSO is used to authenticate users and provide access to the platform. It does not necessarily provide ongoing user profile synchronization.
If you would like user profiles, employee information, or other user data to be automatically synchronized with the platform in addition to enabling SSO, please refer to our documentation on HR Integrations.