Overview

ProBeya supports per-organization Single Sign-On (SSO) via OIDC (OpenID Connect) and SAML 2.0. When SSO is enabled, members authenticate through your corporate identity provider instead of using email and password. This centralizes access control, simplifies onboarding and offboarding, and satisfies enterprise security requirements.

SSO configuration is available on Business and Enterprise plans.

Supported Identity Providers

ProBeya has been tested with the following identity providers:

ProviderProtocolNotes
OktaOIDC / SAMLFully supported with automatic user provisioning
Microsoft Entra ID (Azure AD)OIDC / SAMLSupports group-based role mapping
Google WorkspaceOIDCUses Google’s OAuth 2.0 discovery endpoint
OneLoginSAMLCertificate-based authentication
Auth0OIDCCustom domains supported
Any SAML 2.0 providerSAMLGeneric configuration with manual metadata entry

Configuring OIDC

1

Open SSO Settings

Navigate to Settings > Security > Single Sign-On in your organization admin panel.

2

Select OIDC Protocol

Choose OpenID Connect as the SSO protocol.

3

Enter Provider Details

Fill in the following fields from your identity provider’s application registration:

  • Issuer URL — the OIDC discovery base URL (e.g., https://login.microsoftonline.com/{tenant}/v2.0)
  • Client ID — the application/client ID assigned by your IdP
  • Client Secret — the client secret generated by your IdP
4

Test the Connection

Click Test Connection to verify that ProBeya can reach your IdP’s .well-known/openid-configuration endpoint and retrieve the discovery document. A green check confirms success.

5

Save Configuration

Click Save to store the SSO configuration. The client secret is encrypted at rest and never returned in API responses after initial save.

Configuring SAML 2.0

1

Open SSO Settings

Navigate to Settings > Security > Single Sign-On.

2

Select SAML Protocol

Choose SAML 2.0 as the SSO protocol.

3

Enter IdP Metadata

Provide the following from your identity provider:

  • SSO URL — the IdP’s SAML sign-in endpoint
  • Entity ID — the IdP’s entity identifier
  • X.509 Certificate — the IdP’s public signing certificate (PEM format)
4

Configure Your IdP

In your identity provider, create a new SAML application with:

  • ACS URL: https://{your-org}.probeya.com/api/auth/callback/saml
  • Entity ID: https://{your-org}.probeya.com
  • Name ID Format: Email address
5

Test and Save

Click Test SSO to perform a round-trip authentication. If successful, save the configuration.

Enforcing SSO

After saving the SSO configuration, you can optionally enforce SSO for all organization members:

  1. Toggle Enforce SSO in the SSO settings panel.
  2. Set a grace period (1-30 days) to allow existing members to transition.
  3. After the grace period, password-based login is disabled and all members must authenticate via SSO.

When SSO is enforced, members who have not linked their SSO account will be locked out after the grace period expires. Ensure all members have tested SSO login before enforcement.

Security Model

  • Only organization owners and admins can view or modify SSO settings.
  • The OIDC client secret is stored encrypted and never returned in API responses — the UI displays a masked placeholder (••••••••••••).
  • When updating SSO settings, if the client secret field is left empty or matches the mask placeholder, the existing secret is preserved.
  • All SSO configuration changes are recorded in the organization audit log.
  • SSO configuration is scoped per organization — each tenant on ProBeya has its own independent SSO setup.

Removing SSO

To remove SSO and revert to password-based authentication:

  1. Navigate to Settings > Security > Single Sign-On.
  2. Click Delete Configuration.
  3. Confirm the deletion.

Deleting SSO configuration does not remove user accounts. Members will be prompted to set a password on their next login if they do not have one.

Troubleshooting

IssueResolution
“Test Connection” failsVerify the Issuer URL is correct and accessible from the internet. Check that the Client ID and Secret match your IdP application.
Users see “SSO not configured”Ensure the SSO configuration is saved and the user is accessing the correct organization subdomain.
SAML assertion errorsConfirm that the ACS URL and Entity ID in your IdP match the values shown in ProBeya’s SSO settings.
Users cannot log in after enforcementCheck that the grace period has not expired for users who have not yet linked their SSO account. An admin can temporarily disable enforcement.