Single Sign-On (SSO)
On the Enterprise plan, members can sign in through your identity provider (IdP) using SAML 2.0 or OpenID Connect. Tested IdPs include Microsoft Entra ID, Okta, Google Workspace, OneLogin and JumpCloud.
Set up SAML
Start in Veyli
Go to Settings → SSO → Configure SAML. Copy the two values Veyli shows:
| Field | Value |
|---|---|
| ACS (reply) URL | https://app.veyli.cloud/sso/saml/acs |
| Entity ID (audience) | https://app.veyli.cloud/sso/saml/<workspace-id> |
Create the app in your IdP
Create a new SAML application with the values above. Send these attributes:
| Attribute | Required | Purpose |
|---|---|---|
email (NameID) | ✓ | Identifies the member |
firstName, lastName | Display name | |
groups | Role and scope mapping |
Paste IdP metadata
Paste the IdP metadata URL (or upload the XML) into Veyli.
Verify your domain
Add the TXT record Veyli shows to your DNS (e.g. veyli-verification=… on example.com). Only users with verified-domain emails can sign in via SSO.
Test, then enforce
Click Test sign-in. Once it works, turn on Require SSO to block password and social sign-in for your domain. Owners keep a password fallback in case your IdP is down.
Role mapping
Map IdP groups to Veyli roles and scopes, e.g. signage-admins → Admin, store-managers-lisbon → Viewer (scoped to Lisbon store). Mappings are applied at every sign-in.
Just-in-time provisioning
With JIT provisioning on, anyone from your verified domain who signs in via SSO gets a member account automatically, with the default role you choose (usually Viewer). SCIM provisioning and deprovisioning is also available — ask your account manager.
Enabling Require SSO signs out all members of your domain who used a password. Tell your team before you switch it on.