Skip to Content
WorkspaceSingle Sign-On (SSO)

Single Sign-On (SSO)

On the Enterprise plan, members can sign in through your identity provider (IdP) using SAML 2.0 or OpenID Connect. Tested IdPs include Microsoft Entra ID, Okta, Google Workspace, OneLogin and JumpCloud.

Set up SAML

Start in Veyli

Go to Settings → SSO → Configure SAML. Copy the two values Veyli shows:

FieldValue
ACS (reply) URLhttps://app.veyli.cloud/sso/saml/acs
Entity ID (audience)https://app.veyli.cloud/sso/saml/<workspace-id>

Create the app in your IdP

Create a new SAML application with the values above. Send these attributes:

AttributeRequiredPurpose
email (NameID)✓Identifies the member
firstName, lastNameDisplay name
groupsRole and scope mapping

Paste IdP metadata

Paste the IdP metadata URL (or upload the XML) into Veyli.

Verify your domain

Add the TXT record Veyli shows to your DNS (e.g. veyli-verification=… on example.com). Only users with verified-domain emails can sign in via SSO.

Test, then enforce

Click Test sign-in. Once it works, turn on Require SSO to block password and social sign-in for your domain. Owners keep a password fallback in case your IdP is down.

Role mapping

Map IdP groups to Veyli roles and scopes, e.g. signage-admins → Admin, store-managers-lisbon → Viewer (scoped to Lisbon store). Mappings are applied at every sign-in.

Just-in-time provisioning

With JIT provisioning on, anyone from your verified domain who signs in via SSO gets a member account automatically, with the default role you choose (usually Viewer). SCIM provisioning and deprovisioning is also available — ask your account manager.

Enabling Require SSO signs out all members of your domain who used a password. Tell your team before you switch it on.