Skip to main content

Set up SAML single sign-on (Self Serve)

SafeBase supports SAML 2.0 single sign-on with just-in-time (JIT) provisioning. Once SSO is connected, anyone assigned the SafeBase application in your identity provider (IdP) gets access to your Trust Center the first time they sign in.

You can now set this up on your own. A SafeBase Admin generates a secure, time-limited setup link, and your IdP administrator completes the connection in a guided assistant that walks through the exact steps for your provider.

Availability

SAML SSO is available on all SafeBase plans. Directory Sync (SCIM provisioning) is a separate feature with its own availability, and is not enabled by connecting SSO.

Read this section before you generate the setup link — the link is on a clock, and a couple of these points are easy to miss.

Who does what

Person

What they need

What they do

SafeBase Admin

The Admin role, or a custom role with edit access to User Management & Authentication

Generates the setup link, and later turns on enforcement

Identity provider admin

Permission to create applications in your IdP (Okta, Entra ID, Google Workspace, and so on)

Completes the setup assistant and tests the connection

These are often two different people. If that is your situation, agree on a time first — the setup link expires five hours after it is opened.

Have these ready

  • Administrator access to your identity provider.

  • Your identity provider’s SAML details — the sign-in URL and the X.509 signing certificate. The assistant asks for these directly, so have your metadata file or metadata URL open.

  • An uninterrupted block of time for your IdP admin. Most connections take 20–40 minutes.

  • A decision on your Default Role for New Members. Everyone who signs in through SSO for the first time receives this role. Admin is a reasonable starting point while you test, then lower it.

  • A second browser or private window, so you can keep your current admin session while testing SSO sign-in.

Important

Do not turn on Require SSO Login until the connection has been created and tested. Enforcing SSO before the connection works can lock your team out of SafeBase.

Supported identity providers

  • Any provider supporting SAML 2.0 can connect to SafeBase. This includes Okta, Microsoft Entra ID (formerly Azure AD), Google Workspace, OneLogin, JumpCloud, AD FS, Keycloak, and PingFederate.

  • The setup assistant employs a universal SAML workflow rather than individual wizards for each provider. Regardless of your chosen IdP, the configuration involves exchanging two specific sets of information:

  • From SafeBase to your IdP: The assistant provides your audience URI and sign-in (ACS) URL for you to copy.

  • From your IdP to SafeBase: You will paste your X.509 signing certificate and sign-in URL into the assistant.

Steps for your specific provider

Because the assistant is provider-neutral, use the configuration steps for your identity provider in Integration - Single Sign-On (SSO) — Okta, OneLogin, Google Workspace, Microsoft Entra ID, and JumpCloud each have a section there. Follow those steps to build the application in your IdP, then bring the values back to the assistant.

Part 1: Start setup in SafeBase

  1. Sign in to SafeBase as an Admin and go to Settings → User Management & Authentication.

  2. Find the Security section. Your Connection ID is shown there and is generated for you — it looks like yourcompany-sso. Copy it; some identity providers ask for it while you configure the application.

  3. Next to Single Sign-On, check the status. A new account reads Not started.

  4. Click Configure SSO. A confirmation dialog explains the two time limits — read it, then confirm.

  5. Click Initiate setup. The setup assistant opens in a new browser tab and the status changes to Setup in progress with a countdown.

  6. If your IdP admin is a different person, send them the address of that new tab. Treat that link like a password — anyone who has it can configure your connection.

Time limits to consider

Clock

Starts when

Length

Time to begin

You click Configure SSO

5 days

Time to finish

The link is opened for the first time

5 hours

The five-hour window cannot be extended. If it runs out, there is no way to recover the work done on that Configure link — return to the Security section and click Restart setup to generate a fresh link.

What the buttons do

Button

When you see it

What it does

Configure SSO

No setup has been started

Creates a setup link

Initiate setup

A link exists but has never been opened

Opens the assistant and starts the 5-hour clock

Continue setup

The link has been opened and is still valid

Reopens the assistant where you left off

Restart setup

The link has expired

Generates a new link

Edit setup

A connection already exists

Reopens the assistant to change the existing connection

Revoke setup

The link has been opened and is still valid

Invalidates the link immediately

After revoking, wait a few seconds before starting a new setup — SafeBase finishes cleaning up the old link first.

Part 2: Complete the setup assistant

This part happens in the assistant, outside SafeBase. It follows a single SAML path, so the screens are the same no matter which identity provider you use.

  1. Copy the values SafeBase gives you. The assistant shows the sign-in (ACS) URL and audience URI for your connection.

  2. Create a SAML application in your identity provider. Paste in the two values above, using the section for your provider in [Integration: Single Sign-On (SSO)] for the exact screens.

  3. Copy your provider’s values back. The assistant asks for your sign-in URL and your X.509 signing certificate.

  4. Map user attributes. Match the claims your IdP sends to the fields SafeBase expects. See the table below.

  5. Assign users and groups. Grant the SafeBase application to the people who should have access. Start with a small test group.

  6. Test the connection. The assistant opens a test sign-in in a new tab. Do not move on until this succeeds.

  7. Set up provisioning (optional). Offered only if SCIM provisioning is enabled for your account.

  8. Verify your domain (optional). Offered depending on your account configuration.

Attribute mapping

Getting these wrong is the single most common cause of a connection that authenticates but produces incomplete profiles.

SafeBase field

Typical IdP claim

Required

email

email / mail / user principal name

Yes

firstName

given_name / firstName

Recommended

lastName

family_name / lastName

Recommended

ID

The stable unique identifier for the user

Yes

Map the name attributes even though sign-in works without them. If you skip them, members appear in SafeBase with blank first and last names.

Part 3: After the connection is created

Return to Settings → User Management & Authentication. The SSO status now reads Connected. It can take a moment to update; refresh the page if it has not caught up.

  1. Test the sign-in yourself

    • Open a private or secondary browser window so you keep your current admin session.

    • Sign in to SafeBase through your identity provider.

    • Confirm your name, email, and role are correct on the member record.

  2. Set the default role for new members

    • New people are created in SafeBase the first time they sign in through SSO.

    • They receive whatever Default Role for New Members is set to, so confirm it before you open access to a wider group.

  3. Turn on enforcement

    • Enforcement is the Require SSO Login setting in the Security section. Once it is on, SafeBase members must sign in through your identity provider.

    • You must be signed in through SSO.

    • The toggle stays disabled until you are signed in through your own SAML connection — the tooltip reads “Log in with your SAML account to enforce”. Sign out, sign back in through SSO, then return to this page and turn it on.

What changes when enforcement is on:

  • Existing members are not removed. People who signed in with a password or with Google keep their membership but can no longer sign in. Remove them from the User Management table if they should no longer have access.

  • In-app invitations are turned off. You add people by assigning them the SafeBase application in your identity provider, not by inviting them in SafeBase.

  • Automatic domain join is turned off. Membership comes from your IdP instead.

  • Google sign-in enforcement is cleared. You cannot require both Google and SAML.

If Directory Sync is enabled

Turning on Directory Sync (SCIM) requires SAML and locks Require SSO Login on. Membership is then fully controlled by your identity provider.

Changing your connection later

Click Edit setup in the Security section to reopen the assistant against your existing connection — use this to rotate a certificate, fix an attribute mapping, or change how the application is configured. The same five-hour window applies once the link is opened.

Your email domains are attached to the connection when it is first created, and are used to route people at those domains to your identity provider. If your organization adds or changes an email domain after SSO is connected, contact SafeBase support — that change is not applied to an existing connection automatically.

Troubleshooting

What you see

What to do

First and last names are blank after the first sign-in

Your attribute mapping is incomplete. Fix the mapping in your IdP, then sign out and back in. Clearing your browser cache and site data for SafeBase also helps.

The setup link has expired

Click Restart setup to generate a new one. Nothing you configured in your IdP is lost.

The status is stuck on Setup in progress

The assistant was not finished. Click Continue setup and complete the remaining steps, including the SSO test.

Nothing happens when you click the setup button

Your browser blocked the new tab. Allow pop-ups for SafeBase and try again.

The Require SSO Login toggle is disabled

Either no connection exists yet, or you are not currently signed in through SSO. Sign in through your identity provider first.

Members are not routed to your identity provider

Their email domain may not be attached to the connection. Contact support to have your domains checked.

Sign-in fails with a certificate or signature error

The signing certificate in your IdP has changed or expired. Use Edit setup to update it.

When to contact support instead

  • Your identity provider cannot be configured through the assistant.

  • Your SafeBase account is managed through Drata — authentication for those accounts is managed in Drata, not SafeBase.

  • You need to add or change the email domains attached to your connection.

  • You want Directory Sync (SCIM) provisioning.

Did this answer your question?