SecuritySet up single sign-on

Set up single sign-on

Let your team sign in to Givable with your own identity provider, using OpenID Connect or SAML 2.0.

When you're done, your team signs in to Givable through your identity provider (Entra ID, Okta, Google Workspace and the like), and you decide who gets in and with which role. Most setups take one pasted value on each side.

Before you start: single sign-on is part of the Enterprise plan. You need permission to edit single sign-on settings, and someone who can register an application in your identity provider and add a DNS record for your email domain.

Connect your identity provider

Open single sign-on

Go to Settings, then Single sign-on, then Connection.

Choose a protocol and paste one value

Pick OpenID Connect or SAML 2.0. For OpenID Connect, paste your provider's Discovery URL with the Client ID and Client secret of the application you created for Givable. For SAML 2.0, paste your provider's IdP metadata XML. Enter your Email domain, then select Save.

Copy Givable's values into your identity provider

After saving, the Connection page shows the values your identity provider needs. For OpenID Connect, add the Redirect URI as an allowed redirect URI. For SAML 2.0, use the Assertion consumer service (ACS) URL and the Entity ID (audience), or hand your IT team the Service provider metadata URL to import.

Verify your email domain

Open Domain. Givable shows a TXT record (its Name and Value). Add it at your DNS provider, then check it. Nobody can sign in with single sign-on until the domain is verified.

Test it

Back on Connection, select Test connection. Each check says what to fix if it doesn't pass. Then try signing in: on the sign-in page, select Sign in with SSO and enter your work email.

Sign-in only works for addresses at exactly your verified domain. If your team also uses a subdomain (for example team.example.org), it is a separate domain.

Decide who gets in

  • Provisioning: by default, someone who signs in at your identity provider but isn't a member of your organization is turned away. Turn on Create a membership on first sign-in and choose the role they're given to let them in automatically.
  • Group mapping: give people a role based on the groups your identity provider sends. Name the claim or attribute that carries the groups, map each group to a role (the first match wins), and choose what happens when nothing matches. After someone signs in, the groups their identity provider sent appear below the list so you can copy them.
  • Access: turn on required single sign-on to stop password sign-in for your team. You'll need at least one break-glass account with a password first, so a problem at your identity provider can't lock everybody out.

You can only give roles through single sign-on that you could give yourself.

Settings explained

Troubleshooting

Still stuck?

We're here for you, and no question is too small. Tell us what you were trying to do and what happened, and we'll help you get it sorted.