Single Sign-On (SSO)
Configure SAML 2.0 or OpenID Connect SSO for your organization to centralize authentication through your identity provider.
Overview
ProBeya supports per-organization Single Sign-On (SSO) via OIDC (OpenID Connect) and SAML 2.0. When SSO is enabled, members authenticate through your corporate identity provider instead of using email and password. This centralizes access control, simplifies onboarding and offboarding, and satisfies enterprise security requirements.
SSO configuration is available on Business and Enterprise plans.
Supported Identity Providers
ProBeya has been tested with the following identity providers:
| Provider | Protocol | Notes |
|---|---|---|
| Okta | OIDC / SAML | Fully supported with automatic user provisioning |
| Microsoft Entra ID (Azure AD) | OIDC / SAML | Supports group-based role mapping |
| Google Workspace | OIDC | Uses Google’s OAuth 2.0 discovery endpoint |
| OneLogin | SAML | Certificate-based authentication |
| Auth0 | OIDC | Custom domains supported |
| Any SAML 2.0 provider | SAML | Generic configuration with manual metadata entry |
Configuring OIDC
Open SSO Settings
Navigate to Settings > Security > Single Sign-On in your organization admin panel.
Select OIDC Protocol
Choose OpenID Connect as the SSO protocol.
Enter Provider Details
Fill in the following fields from your identity provider’s application registration:
- Issuer URL — the OIDC discovery base URL (e.g.,
https://login.microsoftonline.com/{tenant}/v2.0) - Client ID — the application/client ID assigned by your IdP
- Client Secret — the client secret generated by your IdP
Test the Connection
Click Test Connection to verify that ProBeya can reach your IdP’s .well-known/openid-configuration endpoint and retrieve the discovery document. A green check confirms success.
Save Configuration
Click Save to store the SSO configuration. The client secret is encrypted at rest and never returned in API responses after initial save.
Configuring SAML 2.0
Open SSO Settings
Navigate to Settings > Security > Single Sign-On.
Select SAML Protocol
Choose SAML 2.0 as the SSO protocol.
Enter IdP Metadata
Provide the following from your identity provider:
- SSO URL — the IdP’s SAML sign-in endpoint
- Entity ID — the IdP’s entity identifier
- X.509 Certificate — the IdP’s public signing certificate (PEM format)
Configure Your IdP
In your identity provider, create a new SAML application with:
- ACS URL:
https://{your-org}.probeya.com/api/auth/callback/saml - Entity ID:
https://{your-org}.probeya.com - Name ID Format: Email address
Test and Save
Click Test SSO to perform a round-trip authentication. If successful, save the configuration.
Enforcing SSO
After saving the SSO configuration, you can optionally enforce SSO for all organization members:
- Toggle Enforce SSO in the SSO settings panel.
- Set a grace period (1-30 days) to allow existing members to transition.
- After the grace period, password-based login is disabled and all members must authenticate via SSO.
When SSO is enforced, members who have not linked their SSO account will be locked out after the grace period expires. Ensure all members have tested SSO login before enforcement.
Security Model
- Only organization owners and admins can view or modify SSO settings.
- The OIDC client secret is stored encrypted and never returned in API responses — the UI displays a masked placeholder (
••••••••••••). - When updating SSO settings, if the client secret field is left empty or matches the mask placeholder, the existing secret is preserved.
- All SSO configuration changes are recorded in the organization audit log.
- SSO configuration is scoped per organization — each tenant on ProBeya has its own independent SSO setup.
Removing SSO
To remove SSO and revert to password-based authentication:
- Navigate to Settings > Security > Single Sign-On.
- Click Delete Configuration.
- Confirm the deletion.
Deleting SSO configuration does not remove user accounts. Members will be prompted to set a password on their next login if they do not have one.
Troubleshooting
| Issue | Resolution |
|---|---|
| “Test Connection” fails | Verify the Issuer URL is correct and accessible from the internet. Check that the Client ID and Secret match your IdP application. |
| Users see “SSO not configured” | Ensure the SSO configuration is saved and the user is accessing the correct organization subdomain. |
| SAML assertion errors | Confirm that the ACS URL and Entity ID in your IdP match the values shown in ProBeya’s SSO settings. |
| Users cannot log in after enforcement | Check that the grace period has not expired for users who have not yet linked their SSO account. An admin can temporarily disable enforcement. |
Was this page helpful?