Skip to main content
Essal Access supports single sign-on via SAML 2.0 and OpenID Connect (OIDC). Once configured, users authenticate through your identity provider (IdP) and are automatically provisioned or matched to existing Essal accounts.

Supported Identity Providers

Essal Access has pre-built connection templates for common IdPs:
  • Okta
  • Microsoft Entra ID (Azure AD)
  • Google Workspace
  • Auth0
  • Generic SAML 2.0
  • Generic OIDC

Configuring SAML 2.0

Step 1: Create the Connection in Essal

Essal will parse the metadata URL and extract the IdP certificate, SSO URL, and entity ID automatically.

Step 2: Configure Your IdP

In your IdP, create a new SAML application and set:

Step 3: Map Claims to Roles

Define how IdP claims translate to Essal roles:

Configuring OIDC

Testing the Login Flow

Use the SSO test endpoint to trigger a login flow without affecting production sessions:
This returns a test login URL you can open in a browser to validate the end-to-end flow.
SSO connections are not activated until you set "status": "active" on the connection object. This allows you to fully test before enabling SSO for your workspace.

Enforcing SSO

Once the connection is validated, enforce SSO for your domain so that password-based login is disabled: