Before you start
- The flock is on Fleet, and you hold a role that manages security (the owner does).
- You can create an app in your identity provider: Okta, Microsoft Entra ID, Google Workspace, Auth0, JumpCloud or any OIDC or SAML 2.0 provider.
- Everything below is on Enterprise, Single sign-on.
Set up OIDC
- Choose Protocol: OIDC, and list the Email domains that sign in here (for example
company.com). One domain belongs to one flock. - In your identity provider, create a web app and register the Redirect URI the page shows (Copy puts it on the clipboard).
- Paste the provider's Issuer URL (such as
https://company.okta.com), the Client ID and the Client secret. The secret is stored encrypted and never shown again. - Choose who someone new signs in as (see below), turn Single sign-on on, and save.
Set up SAML
- Choose Protocol: SAML, and list the Email domains that sign in here.
- Give your identity provider what the page shows: the Entity ID and the ACS URL, or the metadata URL that carries both.
- Paste the Identity provider sign-in URL and its Signing certificate (PEM). The Identity provider entity ID is optional. Assertions must be signed; the address is read from the email attribute or an email NameID.
- Choose who someone new signs in as, turn Single sign-on on, and save.
Who can come in
| Who signs in | What happens |
|---|---|
| A member of the flock | Signs in as themselves. A suspended member is refused. |
| Someone you invited, or your provider provisioned | Joins with the role you gave them. |
| Anyone else on your domains | Joins with the role set in Someone new signs in as, or is refused when it says Nobody new: only people invited or provisioned. |
The address also has to be inside the flock's invite domains, if you set any on Enterprise, Security.
Require single sign-on
With Require single sign-on for these domains, a member on your domains who signed in any other way (Google, GitHub, email and password) is sent to sign in with your provider, and every action answers sso_required until they do. The owner is never held to it, so there is always a way back in if the provider breaks.
Provisioning with SCIM
- Under Provisioning (SCIM), copy the SCIM URL and make a token (Token for names what it is for). The token starts with
fts_and is shown once. - In your identity provider, turn on SCIM 2.0 provisioning with that URL and the token as a bearer token.
- Assign people or groups to the app. Each one joins with their role the first time they sign in with that address.
Deactivating someone at the provider suspends them here; removing them takes them out of the flock. Every change is in the audit log. Revoke a token on the same page. Pair SCIM with Require single sign-on, so switching someone off at the provider switches them off here.
Signing in
People choose Sign in with SSO on the login page and type their work address; FlockTab finds the flock by the domain and sends them to your provider. Passkeys and two-factor still work on top, and are free on every plan: see Account, Security.