SAML single sign-on
With SAML single sign-on, your team logs in through your own identity provider — Okta, Azure AD or any SAML 2.0 IdP. Access is centralized: onboard and offboard people in one place, with your own policies.
What you'll need
- A SAML 2.0 identity provider (Okta, Azure AD, etc.)
- Admin access to configure the IdP
How it works
Climails acts as the service provider. Your IdP authenticates the user and posts a signed assertion back, which Climails verifies before granting the session.
- Metadata — Climails exposes SP metadata your IdP can consume.
- Login — users start sign-in and are redirected to your IdP.
- ACS — the IdP posts the signed response to Climails' assertion consumer endpoint, which validates the certificate and signature.
Set it up
- 1
Register Climails in your IdP
Create a SAML app in Okta/Azure AD using the SP entity ID and ACS URL from Climails' metadata.
- 2
Provide the IdP details
Configure the IdP SSO URL and signing certificate so Climails can verify assertions.
- 3
Test a login
Sign in through the IdP; a valid signed assertion issues the session.
Frequently asked questions
Which identity providers work?
Any SAML 2.0 IdP — Okta and Azure AD are common. Climails validates the signed response against your IdP's certificate.
Is SSO on every plan?
SSO is an enterprise capability. Talk to us to enable it for your workspace.
Does SSO also create accounts?
SSO authenticates logins; to automatically create, update and deactivate users, pair it with SCIM provisioning.
Start sending in minutes
Create a free account, connect your domain and reach your audience across every channel — no credit card needed.
Free plan forever · No credit card required · Set up in minutes