Skip to main content

Set up single sign-on (SSO) with SAML (beta)

How an Enterprise organization admin sets up SAML single sign-on (beta) in Crelate and assigns it to users.

L
Written by Lauren Hickey-Jednat

Single sign-on (SSO) lets your users sign in to Crelate with your organization’s identity provider instead of a Crelate password. SAML 2.0 SSO is a beta feature on the Enterprise plan. A Crelate organization admin sets it up in Settings > Security > Single Sign-On and then assigns it to users.

Crelate supports Okta in two ways. The legacy Okta provider continues to work for existing setups, and SAML single sign-on is the recommended method for new setups, including new Okta setups. For the legacy method, see Add Okta as a single sign-on provider (legacy).


Which SSO providers can you use with SAML?

Any identity provider that supports SAML 2.0 can be configured to work with Crelate. Microsoft Entra ID supports SAML, so it can be used as well. Setup differs for each provider, and much of it depends on your own organization’s configuration. Crelate does not provide provider-specific guides for SAML, so use your provider’s own documentation for details such as creating the SAML application and mapping user attributes.

If you currently use the legacy Okta provider, see Add Okta as a single sign-on provider (legacy) and the section below on moving to SAML.


What do you need before you set up SAML?

  • A Crelate organization admin account and admin access to your identity provider.

  • The Enterprise plan, with single sign-on turned on for your organization. If Single Sign-On does not appear under Security in Settings, contact your Success Manager or Support.

  • An identity provider that sends each user’s email address in its sign-in response, as an email or UPN claim. The email must match the user’s Crelate login email.


What are Crelate’s service provider details?

Enter these values in your identity provider when you create the SAML application for Crelate.

Setting

Value

Entity ID

https://auth.crelate.com/saml

ACS URL (also called the sign-in response URL)

https://auth.crelate.com/Saml2/Acs

Single logout URL (optional)

https://auth.crelate.com/Saml2/Logout

Metadata URL

https://auth.crelate.com/Saml2

If your identity provider can import service provider details from a metadata URL, you can use the Metadata URL instead of entering the other values yourself.


How to add a SAML provider in Crelate

  1. In your identity provider, create a SAML application for Crelate, using the service provider details above.

  2. In Crelate, go to Settings > Security > Single Sign-On.

  3. Select Add, then choose SAML. The Add menu lists only the provider types that are not yet set up. If a type is already configured, it does not appear in the menu.

  4. Enter a Display Name to identify the provider.

  5. Enter your identity provider’s details in one of two ways:

    • Import from metadata. Paste the IdP Metadata URL and select Import from Metadata URL. The URL must start with https and be reachable from the internet. Crelate fills in the other fields for you.

    • Enter the details yourself. Enter the Entity Id, SSO URL, and IdP Certificate (the base64-encoded public signing certificate). SLO URL, the single logout URL, is optional.

  6. Select Allow IdP-Initiated only if you want users to start signing in from your identity provider’s portal as well as from the Crelate sign-in page.

  7. Select Test Connection. A window opens and asks you to sign in at your identity provider. Crelate shows a success or failure message when the test ends, and the test times out after about two minutes.

  8. If the test succeeds, select Save to keep the result.

You can add one provider of each type. If you change the Entity Id, SSO URL, SLO URL, or certificate on a saved provider, Crelate disables it until you test it again.


How to turn on the SAML provider and assign users

  1. On the provider card, select Enable. If the card shows Validate instead, the provider has not passed a test yet. Select Validate, which takes you to Test Connection. Disabled providers show a DISABLED tag.

  2. Go to Settings > Security > Users and select a user.

  3. In Login Type, choose your SAML provider. Only enabled providers appear in the list. The default, Crelate ID, means the user signs in with a Crelate password.

  4. Select Save, then confirm.

Crelate sends the user an invitation email with instructions for signing in. If the user needs another copy, select Resend Invite.


How do users sign in with SAML?

  1. Go to the Crelate sign-in page and enter your email address.

  2. Select Next. Crelate sends you to your identity provider.

  3. Sign in. After you do, you go directly into Crelate.

Users who sign in with SSO no longer use a Crelate password or Crelate two-factor authentication.


What happens when you disable or delete a SAML provider?

Disabling or deleting a SAML provider switches every user assigned to it to a different login type. Users with no Crelate password receive an email to set one. Before you confirm, Crelate shows how many users are affected.

You cannot change a provider’s type after you save it. To switch types, delete the provider and add a new one.


How do you move from a legacy provider to SAML?

Crelate is retiring the older Okta and Azure AD single sign-on providers. A legacy provider that is already set up shows a notice that the configuration is deprecated. To move to SAML:

  1. Add, test, and enable a SAML provider, as described above.

  2. Change each user’s Login Type from the legacy provider to the SAML provider.

  3. After no users remain on the legacy provider, disable and delete it. Crelate does not allow you to delete a legacy provider while it is enabled or while users still use it.


Key takeaway

SAML 2.0 single sign-on is a beta feature on the Enterprise plan. An organization admin enters Crelate’s service provider details in the identity provider, adds a SAML provider in Settings > Security > Single Sign-On, tests the connection, enables it, and assigns it to users as their Login Type. Setup in your identity provider varies, so use that provider’s own documentation.


What's Next?

Did this answer your question?