Configure SAML SSO
Connect your Identity Provider (Okta, Azure AD, or Google Workspace) to enable single sign-on for your workspace.
On this page
What you will build
By the end of this tutorial, members of your workspace will be able to sign in using your organisation's Identity Provider (IdP), without a separate HowlOps password.
- Capability: at least one non-free workspace capability
- Access: Owner or Admin in HowlOps and administrator access to the IdP
The API checks live workspace capabilities. Use Settings → Plan and pricing for current availability.
Concepts
The platform acts as a SAML 2.0 Service Provider (SP). Your IdP authenticates users and sends a signed SAML assertion back to the platform. You need to exchange two pieces of information between the SP (HowlOps) and the IdP:
- SP Metadata: tells the IdP how to address and sign responses for HowlOps
- IdP Metadata: tells HowlOps where to redirect users and how to verify assertion signatures
Step 1: Retrieve your SP Metadata
- In HowlOps, go to Settings → SSO and choose SAML 2.0.
- Note down (or copy) the following values:
| Value | Where it goes |
|---|---|
| SP Metadata URL | Enter into your IdP to auto-configure |
| SP Entity ID | Enter manually into IdP if auto-config is unavailable |
| ACS URL | Enter manually into IdP if auto-config is unavailable |
Step 2: Configure your Identity Provider
Select your IdP:
Okta
- In Okta Admin Console: Applications → Applications → Create App Integration → SAML 2.0 → Next.
- App name:
HowlOps(or any label). Click Next. - In the SAML Settings section:
- Single sign-on URL (ACS URL): paste the ACS URL from HowlOps.
- Audience URI (SP Entity ID): paste the SP Entity ID from HowlOps.
- Name ID format:
EmailAddress - Application username:
Email
- Click Next → Finish.
- In the Sign On tab, click View SAML setup instructions and copy the IdP Metadata URL.
Microsoft Entra ID (Azure AD)
- Azure Portal → Microsoft Entra ID → Enterprise Applications → New application → Create your own application.
- Name:
HowlOps, select Integrate any other application…, click Create. - Go to Single sign-on → SAML.
- In Basic SAML Configuration:
- Identifier (Entity ID): SP Entity ID from HowlOps
- Reply URL (ACS URL): ACS URL from HowlOps
- Save. Under SAML Signing Certificate, copy the App Federation Metadata URL.
Google Workspace
- Google Admin Console → Apps → Web and mobile apps → Add app → Add custom SAML app.
- Name:
HowlOps. Click Continue. - Download the IdP metadata XML or copy the SSO URL, Entity ID, and Certificate.
- In the Service provider details step:
- ACS URL: paste ACS URL from HowlOps
- Entity ID: paste SP Entity ID from HowlOps
- Name ID format:
EMAIL - Name ID: Basic Information > Primary email
- Click Finish.
Step 3: Complete SSO setup in HowlOps
- Go to Settings → SSO and choose SAML 2.0.
- Paste your IdP Metadata URL into the field, or paste the metadata XML.
- Enter your SSO domain, the email domain your users sign in with (e.g.
yourcompany.com). - Click Save configuration.
Step 4: Verify your domain
To prevent another organisation from claiming your email domain, HowlOps requires you to prove DNS control of it before SSO login is allowed.
- Save the configuration once so HowlOps generates the verification record.
- Copy the exact TXT host and value shown in Settings → SSO.
- Publish them in your public DNS zone, then select Verify domain.
Until the domain is verified, SSO login is rejected and you cannot enable Enforce SSO (Step 6). A domain can be claimed by only one organisation: if verification reports "already claimed by another organization", the domain is already verified on a different workspace.
Step 5: Test the connection
- Click Test SSO login in HowlOps.
- A new browser tab opens, redirecting you to your IdP login.
- Log in with your IdP credentials.
- If successful, you are redirected back with a green confirmation banner.
A successful test confirms the SAML exchange is working. Your users can now click Sign in with SSO on the login page and enter their work email.
Step 6: (Optional) Enforce SSO
Enforce mode blocks password-based login for all workspace members: everyone must authenticate through the IdP.
- In Settings → SSO, enable Require SSO for this email domain.
- Click Save configuration.
Before enabling enforcement, confirm every workspace member has access to the IdP. The current password-login path does not exempt workspace owners.
Troubleshooting
| Problem | Likely cause | Fix |
|---|---|---|
| SAML response signature invalid | IdP certificate expired or metadata stale | Re-fetch metadata from IdP and re-save |
| Redirect loop on login | ACS URL or Entity ID mismatch | Check for trailing slash differences |
| User not found after SSO | Email in assertion does not match HowlOps account | Ensure IdP sends email as NameID |
| IdP metadata could not be fetched | Metadata URL unreachable | Paste the metadata XML directly |
| Members locked out after enforce | Members not in IdP | Disable enforce, provision users, re-enable |
| SSO login rejected / "email domain not authorized" | Domain not DNS-verified, or user's email domain differs from the verified SSO domain | Complete Step 4 (verify the domain); ensure users sign in with an email on the verified domain |
What's next
- Concepts: Plans & capabilities: capabilities and the SSO security baseline
- How-to: Rotate API tokens: manage API access
Was this page helpful?