Security

Setting Up Single Sign-On (SSO)

How to configure SAML or OIDC single sign-on for your OptoGlide workspace.

Supported identity providers

OptoGlide supports SAML 2.0 and OIDC-based single sign-on, tested with Microsoft Entra ID, Google Workspace, and Okta, and compatible with any standards-compliant identity provider.

Configuring SSO

  1. Navigate to Workspace Settings > Security > Single Sign-On.
  2. Select your identity provider type, SAML or OIDC.
  3. Enter the configuration details provided by your identity provider, including the issuer URL and signing certificate for SAML, or the client ID and client secret for OIDC.
  4. Test the connection using the “Test SSO login” option before enforcing it workspace-wide.

Enforcing SSO for all users

Once tested successfully, enable “Require SSO for all members” to disable password-based login for your workspace. Workspace owners retain a break-glass password login option in case of identity provider outages, accessible only from a pre-registered recovery email.

Assigning roles via SSO groups

Enterprise plans support mapping identity provider groups directly to OptoGlide roles, so a user added to a specific group in your identity provider automatically receives the corresponding OptoGlide permissions.

Troubleshooting SSO login issues

If users cannot log in after SSO is enabled, confirm the signing certificate has not expired and that the user’s email in your identity provider matches their OptoGlide account email exactly.

Still need help?

Reach our support team directly for anything not covered here.