SSO/SAML setup
Single sign-on (SSO) lets your team sign in to Renewly through your company's own login system, called an identity provider. SAML is the standard that connects the two.
SAML sign-in is not live yet. You can save your identity provider's details in Renewly today, but nobody signs in through SAML yet, even if you switch a setup on. Your team keeps signing in the way they do now.
How your team signs in today
Every Renewly account can sign in with:
- a sign-in link sent by email
- a Google or Microsoft work account
- a passkey (fingerprint, face or security key) - see Passkeys
If your company already uses Google Workspace or Microsoft 365, the Google and Microsoft buttons let your team use those accounts now.
Supported providers
You can save details for these identity providers:
- Okta
- Azure AD
- Google Workspace
- OneLogin
- Custom SAML, for any other provider
Saving your SSO details
Only owners and admins of a team workspace can do this. You will need three details from your identity provider's admin console.
- Go to Settings → SSO (under Compliance).
- Click Add SSO Provider.
- Choose your identity provider from the Provider list.
- Fill in Entity ID (Issuer), SSO URL (Login endpoint) and X.509 Certificate. Your identity provider shows all three.
- Optionally, fill in Allowed Domains: the email domains that may use SSO, such as yourcompany.com, separated by commas.
- Click Create Configuration.
The certificate is stored encrypted. You can save one setup per identity provider. Each saved setup has an Enable SSO / Disable SSO button and can be removed at any time.
Requiring SSO for everyone
Each setup has a Require SSO for all users option. It is marked "Sign-in path coming soon" because it does not change how anyone signs in yet. When SAML sign-in goes live, make sure everyone on your team has an account in your identity provider before you turn it on.
FAQ
Can I have multiple SSO providers?
You can save one setup for each provider type, so an organisation can hold setups for more than one provider.
What happens if SSO is disabled?
Nothing changes for your team today, because SAML sign-in is not live yet. Everyone keeps signing in with an email link, Google, Microsoft or a passkey.
Is SSO available on all plans?
Single sign-on is sold as part of our Enterprise plan. See the Enterprise plan on the pricing page.
Still stuck? Write to the founder; it is really him who answers.
