Generic SAML SSO
Connect any SAML 2.0 identity provider to Avaloi with signed assertions, the Avaloi ACS URL, and the email as the NameID.
Use this guide when your provider is not Okta, Entra ID, Google Workspace, OneLogin, or Ping. Avaloi accepts SAML 2.0 with signed assertions. Only the Owner can save the connection. The full flow is in Single sign-on with SAML.
Values to give your provider
Copy these from Company settings, then Single sign-on, under Details for your identity provider. They exist before you connect anything.
| Field | Value |
|---|---|
| ACS or Reply URL | The ACS URL on that page |
| Entity ID or Audience | The Entity ID on that page |
| NameID format | Email address. It must be the person's email. |
| Signing | Sign the assertion. SHA-256 or better. |
| Request signing | Not needed. Avaloi does not sign its requests. |
Values to give Avaloi
Choose Enable, then give one of:
- the metadata URL,
- the metadata XML, or
- the provider's entity ID, sign-in URL, and signing certificate.
Then list the email domains you own, add the DNS TXT record under Domain proof, and choose Verify domain and Test connection.
Rules
- Assertions must be signed. Unsigned and changed responses are refused.
- Avaloi creates a person at their first sign-in when just-in-time provisioning is on.
- Mandatory single sign-on closes passwords, Google, and GitHub for your domains. The Owner and the exceptions list keep a password.
- SCIM is not available.
Quick answers
My provider wants an audience. Use the Entity ID from the Single sign-on page.
Can the NameID be an opaque ID?
No. Avaloi uses the email, so send it as the NameID or as an email attribute.
I turned on mandatory sign-on and people are stuck. Turn it off, fix the provider, run Test connection, then turn it on again. The Owner can always sign in with a password.
API
GET /v1/companies/me/ssoPUT /v1/companies/me/ssoDELETE /v1/companies/me/sso
Related
Still stuck?
Email [email protected] with your site name and what you tried, or send us a message.