Generic SAML SSO
Connect any SAML 2.0 identity provider to Avaloi with signed assertions, the Avaloi ACS, and email as the NameID.
Use this guide when your provider is not Okta, Entra ID, Google Workspace, OneLogin, or Ping. Avaloi accepts SAML 2.0 with signed assertions. Only the Owner can save the connection.
Values to give your provider
| Field | Value |
|---|---|
| ACS or Reply URL | https://api.avaloi.com/auth/saml/{company}/acs |
| Start or Login URL | https://api.avaloi.com/auth/saml/{company}/start |
| NameID | Persistent or email. It must be the user's email. |
Replace {company} with your company slug, the slug field from GET /v1/companies/me.
Values to give Avaloi
- Open Company settings, then SSO.
- Choose SAML as the provider.
- Paste the issuer or metadata URL.
- Add the domains you claim.
- Leave Enforce SSO off until a test login works.
Rules
- Assertions must be signed.
- Avaloi creates a user on the first successful login if the email is new (just in time).
- Enforced SSO refuses password and magic link for the claimed domains.
- SCIM is not available.
Quick answers
My provider wants an entity ID or audience. Use the start URL for the entity, as the provider guides do.
Can the NameID be an opaque ID? No. Avaloi matches on verified email, so the NameID must be the email.
I enforced SSO and locked everyone out. Turn Enforce SSO off so members can sign in another way, fix the provider, then enforce again. See SSO.
API
GET /v1/companies/me/ssoPUT /v1/companies/me/ssoDELETE /v1/companies/me/sso
Related
Still stuck?
Email [email protected] with your site name and what you tried, or send us a message.