Tutorials

Configure SAML SSO

Connect your Identity Provider (Okta, Azure AD, or Google Workspace) to enable single sign-on for your workspace.

What you will build

By the end of this tutorial, members of your workspace will be able to sign in using your organisation's Identity Provider (IdP), without a separate HowlOps password.

  • Capability: at least one non-free workspace capability
  • Access: Owner or Admin in HowlOps and administrator access to the IdP

The API checks live workspace capabilities. Use Settings → Plan and pricing for current availability.


Concepts

The platform acts as a SAML 2.0 Service Provider (SP). Your IdP authenticates users and sends a signed SAML assertion back to the platform. You need to exchange two pieces of information between the SP (HowlOps) and the IdP:

  • SP Metadata: tells the IdP how to address and sign responses for HowlOps
  • IdP Metadata: tells HowlOps where to redirect users and how to verify assertion signatures

Step 1: Retrieve your SP Metadata

  1. In HowlOps, go to Settings → SSO and choose SAML 2.0.
  2. Note down (or copy) the following values:
ValueWhere it goes
SP Metadata URLEnter into your IdP to auto-configure
SP Entity IDEnter manually into IdP if auto-config is unavailable
ACS URLEnter manually into IdP if auto-config is unavailable

Step 2: Configure your Identity Provider

Select your IdP:

Okta

  1. In Okta Admin Console: Applications → Applications → Create App Integration → SAML 2.0 → Next.
  2. App name: HowlOps (or any label). Click Next.
  3. In the SAML Settings section:
    • Single sign-on URL (ACS URL): paste the ACS URL from HowlOps.
    • Audience URI (SP Entity ID): paste the SP Entity ID from HowlOps.
    • Name ID format: EmailAddress
    • Application username: Email
  4. Click Next → Finish.
  5. In the Sign On tab, click View SAML setup instructions and copy the IdP Metadata URL.

Microsoft Entra ID (Azure AD)

  1. Azure Portal → Microsoft Entra ID → Enterprise Applications → New application → Create your own application.
  2. Name: HowlOps, select Integrate any other application…, click Create.
  3. Go to Single sign-on → SAML.
  4. In Basic SAML Configuration:
    • Identifier (Entity ID): SP Entity ID from HowlOps
    • Reply URL (ACS URL): ACS URL from HowlOps
  5. Save. Under SAML Signing Certificate, copy the App Federation Metadata URL.

Google Workspace

  1. Google Admin Console → Apps → Web and mobile apps → Add app → Add custom SAML app.
  2. Name: HowlOps. Click Continue.
  3. Download the IdP metadata XML or copy the SSO URL, Entity ID, and Certificate.
  4. In the Service provider details step:
    • ACS URL: paste ACS URL from HowlOps
    • Entity ID: paste SP Entity ID from HowlOps
    • Name ID format: EMAIL
    • Name ID: Basic Information > Primary email
  5. Click Finish.

Step 3: Complete SSO setup in HowlOps

  1. Go to Settings → SSO and choose SAML 2.0.
  2. Paste your IdP Metadata URL into the field, or paste the metadata XML.
  3. Enter your SSO domain, the email domain your users sign in with (e.g. yourcompany.com).
  4. Click Save configuration.

Step 4: Verify your domain

To prevent another organisation from claiming your email domain, HowlOps requires you to prove DNS control of it before SSO login is allowed.

  1. Save the configuration once so HowlOps generates the verification record.
  2. Copy the exact TXT host and value shown in Settings → SSO.
  3. Publish them in your public DNS zone, then select Verify domain.

Until the domain is verified, SSO login is rejected and you cannot enable Enforce SSO (Step 6). A domain can be claimed by only one organisation: if verification reports "already claimed by another organization", the domain is already verified on a different workspace.


Step 5: Test the connection

  1. Click Test SSO login in HowlOps.
  2. A new browser tab opens, redirecting you to your IdP login.
  3. Log in with your IdP credentials.
  4. If successful, you are redirected back with a green confirmation banner.

A successful test confirms the SAML exchange is working. Your users can now click Sign in with SSO on the login page and enter their work email.


Step 6: (Optional) Enforce SSO

Enforce mode blocks password-based login for all workspace members: everyone must authenticate through the IdP.

  1. In Settings → SSO, enable Require SSO for this email domain.
  2. Click Save configuration.

Before enabling enforcement, confirm every workspace member has access to the IdP. The current password-login path does not exempt workspace owners.


Troubleshooting

ProblemLikely causeFix
SAML response signature invalidIdP certificate expired or metadata staleRe-fetch metadata from IdP and re-save
Redirect loop on loginACS URL or Entity ID mismatchCheck for trailing slash differences
User not found after SSOEmail in assertion does not match HowlOps accountEnsure IdP sends email as NameID
IdP metadata could not be fetchedMetadata URL unreachablePaste the metadata XML directly
Members locked out after enforceMembers not in IdPDisable enforce, provision users, re-enable
SSO login rejected / "email domain not authorized"Domain not DNS-verified, or user's email domain differs from the verified SSO domainComplete Step 4 (verify the domain); ensure users sign in with an email on the verified domain

What's next

Was this page helpful?