Docs

Single sign-on and SCIM

Send people on your company's email domains to your own identity provider to sign in, and let that provider add, suspend and remove them here. Both are part of Enterprise, on Fleet.

Before you start

  • The flock is on Fleet, and you hold a role that manages security (the owner does).
  • You can create an app in your identity provider: Okta, Microsoft Entra ID, Google Workspace, Auth0, JumpCloud or any OIDC or SAML 2.0 provider.
  • Everything below is on Enterprise, Single sign-on.

Set up OIDC

  1. Choose Protocol: OIDC, and list the Email domains that sign in here (for example company.com). One domain belongs to one flock.
  2. In your identity provider, create a web app and register the Redirect URI the page shows (Copy puts it on the clipboard).
  3. Paste the provider's Issuer URL (such as https://company.okta.com), the Client ID and the Client secret. The secret is stored encrypted and never shown again.
  4. Choose who someone new signs in as (see below), turn Single sign-on on, and save.

Set up SAML

  1. Choose Protocol: SAML, and list the Email domains that sign in here.
  2. Give your identity provider what the page shows: the Entity ID and the ACS URL, or the metadata URL that carries both.
  3. Paste the Identity provider sign-in URL and its Signing certificate (PEM). The Identity provider entity ID is optional. Assertions must be signed; the address is read from the email attribute or an email NameID.
  4. Choose who someone new signs in as, turn Single sign-on on, and save.

Who can come in

Who signs inWhat happens
A member of the flockSigns in as themselves. A suspended member is refused.
Someone you invited, or your provider provisionedJoins with the role you gave them.
Anyone else on your domainsJoins with the role set in Someone new signs in as, or is refused when it says Nobody new: only people invited or provisioned.

The address also has to be inside the flock's invite domains, if you set any on Enterprise, Security.

Require single sign-on

With Require single sign-on for these domains, a member on your domains who signed in any other way (Google, GitHub, email and password) is sent to sign in with your provider, and every action answers sso_required until they do. The owner is never held to it, so there is always a way back in if the provider breaks.

Provisioning with SCIM

  1. Under Provisioning (SCIM), copy the SCIM URL and make a token (Token for names what it is for). The token starts with fts_ and is shown once.
  2. In your identity provider, turn on SCIM 2.0 provisioning with that URL and the token as a bearer token.
  3. Assign people or groups to the app. Each one joins with their role the first time they sign in with that address.

Deactivating someone at the provider suspends them here; removing them takes them out of the flock. Every change is in the audit log. Revoke a token on the same page. Pair SCIM with Require single sign-on, so switching someone off at the provider switches them off here.

Signing in

People choose Sign in with SSO on the login page and type their work address; FlockTab finds the flock by the domain and sends them to your provider. Passkeys and two-factor still work on top, and are free on every plan: see Account, Security.