Skip to content

Single sign-on

Each organization can connect its own identity provider (IdP) with OpenID Connect (OIDC) or SAML 2.0. Owners and admins configure it.

Replace <org> below with your workspace address (for example acme).

Value URL
OIDC redirect URI (sign-in) https://<org>.gxpvalidate.app/sso/oidc/callback/<org>/
OIDC redirect URI (signing step-up) https://gxpvalidate.app/app/account/reauth/sso/callback/
SAML ACS (reply) URL https://<org>.gxpvalidate.app/sso/saml/acs/<org>/
SAML SP metadata https://<org>.gxpvalidate.app/sso/saml/metadata/<org>/

Who can sign in with SSO

SSO never adds strangers to your organization. A person signing in through your IdP is admitted only if they are already a user of your organization or have an open invitation. An email address that belongs to another organization is refused.

Configure SSO

With OIDC, register both redirect URIs from the table above: the first is for signing in, the second for re-authenticating when someone signs a record (SSO step-up). SAML has no step-up, so SAML users sign with a passkey or a password.

  1. Register GxPValidate as an application in your IdP (see the provider sections below).
  2. In GxPValidate, open Organization → Configure identity provider and enter the provider details.
  3. OIDC: issuer URL, client ID and client secret. Scopes default to openid email profile.
  4. SAML: IdP entity ID, IdP single sign-on URL, and the IdP's X.509 signing certificate (PEM). Map the email attribute if your IdP does not send it as the NameID.
  5. Test the connection from the same page and complete a sign-in. SSO cannot be enabled until the test succeeds.
  6. Turn on SSO enabled. The sign-in page now offers Sign in with SSO.
  7. When everyone can sign in through the IdP, turn on SSO enforced. See Enforce SSO.

Client secrets and certificates are stored encrypted.

Microsoft Entra ID

OIDC (recommended)

  1. In the Entra admin center, go to App registrations → New registration.
  2. Supported account types: Accounts in this organizational directory only.
  3. Redirect URI: platform Web, value https://<org>.gxpvalidate.app/sso/oidc/callback/<org>/. After registering, add the second (step-up) redirect URI https://gxpvalidate.app/app/account/reauth/sso/callback/ under Authentication.
  4. Under Certificates & secrets, create a client secret and copy its value.
  5. In GxPValidate enter:
  6. Issuer: https://login.microsoftonline.com/<tenant-id>/v2.0
  7. Client ID: the Application (client) ID
  8. Client secret: the value from step 4
  9. Make sure users have an email address in Entra ID (the email claim).

SAML

  1. Enterprise applications → New application → Create your own application (non-gallery), then Single sign-on → SAML.
  2. Identifier (Entity ID): https://<org>.gxpvalidate.app/sso/saml/metadata/<org>/. Reply URL (ACS): https://<org>.gxpvalidate.app/sso/saml/acs/<org>/.
  3. Download the Certificate (Base64) and copy the Login URL and Microsoft Entra Identifier into GxPValidate.
  4. Assign the users or groups who may sign in.

Okta

OIDC

  1. Applications → Create App Integration → OIDC - OpenID Connect → Web Application.
  2. Sign-in redirect URIs: https://<org>.gxpvalidate.app/sso/oidc/callback/<org>/ and, for signing step-up, https://gxpvalidate.app/app/account/reauth/sso/callback/.
  3. Assign the users or groups.
  4. In GxPValidate enter the issuer https://<your-okta-domain> (or your custom authorization server's issuer), the client ID and the client secret.

SAML

  1. Create App Integration → SAML 2.0.
  2. Single sign-on URL: https://<org>.gxpvalidate.app/sso/saml/acs/<org>/. Audience URI (SP Entity ID): https://<org>.gxpvalidate.app/sso/saml/metadata/<org>/. Name ID format: EmailAddress.
  3. From Sign On → View SAML setup instructions, copy the IdP SSO URL, the issuer and the X.509 certificate into GxPValidate.

Google Workspace

OIDC

  1. In Google Cloud console, APIs & Services → Credentials → Create credentials → OAuth client ID, type Web application. Set the OAuth consent screen to Internal.
  2. Authorized redirect URIs: https://<org>.gxpvalidate.app/sso/oidc/callback/<org>/ and, for signing step-up, https://gxpvalidate.app/app/account/reauth/sso/callback/.
  3. In GxPValidate enter the issuer https://accounts.google.com, the client ID and the client secret.

SAML

  1. In the Admin console, Apps → Web and mobile apps → Add app → Add custom SAML app.
  2. Copy the SSO URL, Entity ID and certificate into GxPValidate.
  3. ACS URL: https://<org>.gxpvalidate.app/sso/saml/acs/<org>/. Entity ID: https://<org>.gxpvalidate.app/sso/saml/metadata/<org>/. Name ID format EMAIL, Name ID Basic Information → Primary email.
  4. Turn the app ON for the right organizational units.

Email domain routing

Set your organization's email domain in Organization settings. On the shared sign-in page, people whose email is on that domain are directed to your IdP. If two organizations claim the same domain, neither is routed automatically.

Enforce SSO

With SSO enforced, password sign-in is refused for your organization's users and they must use Sign in with SSO. Users who joined through SSO have no password at all. Turn enforcement on only after an admin has tested SSO sign-in, so you are not locked out.

With OIDC single sign-on, signing a record can re-authenticate through your IdP (SSO step-up). With SAML, users sign with a passkey, or a password if SSO is not enforced. See Re-authentication.