Skip to content

Guide

Set up single sign-on (SSO)

Branding & settings · 5 min read

Single sign-on (SSO) lets members sign in to your community with their work account from your organization's identity provider (IdP), such as Okta, Microsoft Entra ID (formerly Azure AD), or Google. Mateflow supports SAML 2.0 and OIDC (OpenID Connect).

Who can do this: Owners and admins. · Where: Web (admin console). Members use SSO on the web, and with OIDC also in the Mateflow app. · Plan: SSO depends on your platform plan. If yours doesn't include it, the SSO page says which plans do. If you move to a plan without SSO, SSO stops working and members sign in with your other methods; your settings are kept for when you upgrade.

Connect your identity provider with SAML 2.0 or OIDC

Connecting your identity provider requires admin access to it.

  1. Go to Admin → Settings → SSO, choose an SSO Protocol on the SSO Configuration tab, and create a matching app in your IdP.
  2. For SAML 2.0, copy the SP Entity ID and ACS URL from SP Information into the IdP app, or give it the SP Metadata XML. Enter the IdP SSO URL, IdP Entity ID, and IdP Certificate. Parse Metadata can fill in the first two from a Metadata URL or Metadata XML (optional).
  3. For OIDC, enter the Issuer URL, Client ID, Client Secret, and Scopes (comma separated), such as openid, email, profile.
  4. Click Save SSO Configuration. For OIDC, add the Redirect URI (callback URL) now shown under SP Information to your IdP app.
  5. Click Test Connection, which checks the saved settings. If it shows Test Failed, fix the listed Errors and save again.
  6. Turn on the switch under SSO Status and save.

Choose an SSO login policy

Your SSO login policy decides which other sign-in methods stay available. On the Login Policy tab, choose a Login Mode:

  • SSO + Password: SSO or email and password. Social login is hidden.
  • SSO + Social + Password: all methods stay available.
  • SSO Only: everyone must use SSO. Password and social login are blocked.

Before choosing SSO Only, make sure Test Connection passes and add a recovery admin, or a broken IdP setup could lock everyone out.

You can also set the SSO Button Text and Allowed Email Domains (comma separated). With domains set, members must enter a matching work email to continue.

Turn JIT user provisioning on or off

JIT (just-in-time) user provisioning decides what happens the first time someone signs in with SSO. It's the JIT User Provisioning switch on the User Sync tab, on by default.

  • On: a first SSO sign-in links the person to the account with the same email, or creates one.
  • Off: only people who have used SSO before can sign in with it. Existing members who have never used SSO can't, even if their email matches.

Before turning JIT off, make sure everyone who needs SSO has used it once.

Add recovery admins for SSO

Recovery admins can sign in with a password when SSO fails, even under SSO Only. Each one must be an owner or admin of your community and have a password on their account.

  1. On the User Sync tab, enter user IDs in Recovery Admin User IDs (comma separated). To find an ID, go to Admin → Members → All Members, click the person, and use Copy ID next to Member ID.
  2. Click Save SSO Configuration.

Under SSO Only, recovery admins click Recovery admin sign in on the sign-in page and enter their email and password. Two-factor authentication still applies.

Review SSO sign-ins in the audit log

The SSO audit log records SSO sign-ins, accounts created by JIT provisioning, configuration changes, and errors. The Audit tab shows Total SSO Users, SSO Logins (Last 30 Days), and Last SSO Login. Click Open Audit Logs for the full list, filterable by Action (SSO Login, Auto User Provisioning, Config Change, or Error), Start Date, and End Date.

What members see when they sign in with SSO

Members start on your community's sign-in page, click your SSO button (Use enterprise SSO by default), sign in at your IdP, and return signed in. Two-factor authentication still applies.

Sign-in must start on your community. Clicking the app tile in your IdP's portal (IdP-initiated sign-in) isn't supported.

In the Mateflow app, members can sign in with OIDC (the default button is Sign in with SSO). The app doesn't support SAML: under SSO Only it asks members to use the web; otherwise it shows only the other methods.

Troubleshooting SSO sign-in

Symptom: Members get an error when they start from the IdP's app portal. Why it happens: IdP-initiated sign-in isn't supported. Fix: Have members start on your community's sign-in page, or point the app tile's sign-on URL there if your IdP allows it.

Symptom: Existing members can't use SSO after you turned off JIT. Why it happens: With JIT off, only people who used SSO before can use it. Fix: Turn JIT User Provisioning back on until each has signed in once.

Symptom: Nobody can sign in under SSO Only. Why it happens: The IdP connection broke. Fix: A recovery admin signs in with Recovery admin sign in and fixes the settings.

Related articles

Was this guide helpful?

Back to guides

Can't find what you need?

If you're a member of a community, its admins are the right people to ask. If you're building or running one on Mateflow, our team can help.

Start free trial