SSO
Connect one SAML identity provider, prove your domains, test it, then make it mandatory so people sign in only through your provider.
SSO is for Enterprise accounts only. Individual and Business accounts do not have it, and the Settings menu does not show it to them. Enterprise is custom and set up with sales. See Account types.
On an Enterprise account, the Owner connects one SAML identity provider per company. People whose email is on a domain you verified sign in through that provider, and Avaloi creates them at their first sign-in.
Steps
- Open Company settings, then Single sign-on, and copy the details your provider needs.
- Choose Enable and paste your provider's metadata.
- Verify your domains with a DNS TXT record.
- Choose Test connection, then sign in once through Sign in with your company.
- Turn on Mandatory single sign-on if you want it.
The whole flow, with provisioning, role mapping, exceptions, and certificate rotation, is in Single sign-on with SAML.
Provider guides: Okta, Entra ID, Google Workspace, OneLogin, Ping, and generic SAML.
Quick answers
Can an Admin set up SSO? No. Only the Owner.
Is OpenID Connect available? Not yet.
Is SCIM provisioning available? No. Avaloi creates people at their first sign-in.
Does support paste my metadata for me? No. The Owner pastes it in the dashboard.
Related
Still stuck?
Email [email protected] with your site name and what you tried, or send us a message.