Set Up Single Sign-On (SSO)
Owners and admins can configure SSO with an OIDC or SAML identity provider and choose invite-only or just-in-time provisioning.
Limited availabilityWhere to find it: Settings → SSO (/app/settings/sso)
What this guide helps you do
Let your team sign in with your organization’s identity provider.
Who this applies to
Owners and admins. SSO has been verified with a test identity provider; no production identity-provider pilot has been completed yet.
Before you start
- Keep one owner able to sign in with a password until SSO is confirmed working.
- Multi-factor authentication is handled by your identity provider; Klarstig does not offer its own MFA settings.
Steps
- Open SSO settings and choose the protocol.
- Copy the Klarstig service-provider details (SP entityID and ACS URL for SAML) into your identity provider.
- Enter your identity provider details: issuer URL and client ID for OIDC, or IdP entityID, SSO URL and certificate for SAML.
- Choose Invite only or Just-in-time provisioning and save, then test with one account before rolling out.
What you should see
Users from your identity provider can sign in to the workspace; the connection status shows the result.
Troubleshooting
Sign-in fails after setup.
Check the issuer or entityID, the email attribute mapping and the certificate. See Sign-in problems.
Related guides
- Data Processing Addendum and Security SettingsReview and accept the Data Processing Addendum, and see what protects your organization on the Security & data page.
- Workspace Roles and Who Can Do WhatWorkspaces have four roles: Owner, Admin, Member and Viewer. The Team page shows who has which role.
- Sign-In ProblemsReset a forgotten password, get past the bot check and sign in through your organization’s SSO.
Still need help?
Send us a message with your workspace name and what you tried. Don’t include card numbers or passwords.
