Skip to content
Enterprise & agencies

SAML single sign-on

With SAML single sign-on, your team logs in through your own identity provider — Okta, Azure AD or any SAML 2.0 IdP. Access is centralized: onboard and offboard people in one place, with your own policies.

6 min read

What you'll need

  • A SAML 2.0 identity provider (Okta, Azure AD, etc.)
  • Admin access to configure the IdP

How it works

Climails acts as the service provider. Your IdP authenticates the user and posts a signed assertion back, which Climails verifies before granting the session.

  • Metadata — Climails exposes SP metadata your IdP can consume.
  • Login — users start sign-in and are redirected to your IdP.
  • ACS — the IdP posts the signed response to Climails' assertion consumer endpoint, which validates the certificate and signature.

Set it up

  1. 1

    Register Climails in your IdP

    Create a SAML app in Okta/Azure AD using the SP entity ID and ACS URL from Climails' metadata.

  2. 2

    Provide the IdP details

    Configure the IdP SSO URL and signing certificate so Climails can verify assertions.

  3. 3

    Test a login

    Sign in through the IdP; a valid signed assertion issues the session.

SSO pairs naturally with SCIM provisioning — SSO controls how people log in, SCIM controls who exists. See the SCIM guide to automate accounts.

Frequently asked questions

Which identity providers work?

Any SAML 2.0 IdP — Okta and Azure AD are common. Climails validates the signed response against your IdP's certificate.

Is SSO on every plan?

SSO is an enterprise capability. Talk to us to enable it for your workspace.

Does SSO also create accounts?

SSO authenticates logins; to automatically create, update and deactivate users, pair it with SCIM provisioning.

Start sending in minutes

Create a free account, connect your domain and reach your audience across every channel — no credit card needed.

Free plan forever · No credit card required · Set up in minutes

SAML 2.0 single sign-on (SSO) setup — Climails