Settings & AI
Single Sign-On and SCIM
An organization connects its identity provider (Okta, Microsoft Entra ID, Google Workspace, Ping or another SAML 2.0 provider) so members sign in with their work account, and optionally lets the provider create, update and deactivate their Holarch accounts (SCIM 2.0).
Where to find it
- Org admins: the account button (your initials) → Organization Settings → the organization → Single sign-on.
- Members: the sign-in screen → Sign in with single sign-on, or the sign-in link the org admin shares.
Main actions
- Verify an email domain: Add Domain, publish the shown DNS TXT record (name
_holarch-challenge.<domain>), then Check. Single sign-on and SCIM cover only addresses in verified domains. A domain belongs to one organization. - Connect the identity provider: create a SAML application with the shown Entity ID and ACS URL (or its Metadata URL). Paste the provider's metadata XML or URL and choose Read Metadata, or enter its entity ID, sign-in URL and signing certificate. Add a second certificate while the provider rolls its certificate over. Save Identity Provider asks for your password.
- Attributes and roles: the email, name and groups attributes (common names are found without setting them), the role of new members, and groups mapped to Member or Org admin. Roles follow the groups at every sign-in; the last org admin is never demoted.
- Turn on: Single sign-on for this organization needs a saved provider and a verified domain. The first sign-in of a new address creates the account and adds it to the organization. An existing account with that address is linked, and its owner gets an email.
- Require single sign-on: members in the verified domains then sign in only through the identity provider; their other sessions end. Org admins keep their password or passkey, so they can fix a broken setup. Members with other addresses are not affected. API tokens and connected apps keep working until the account is deactivated.
- Two-step sign-in: by default a single sign-on is the first step, and accounts with two-step sign-in still confirm a passkey or code. With Trust the identity provider's multi-factor sign-in on, a sign-in whose provider reports multi-factor authentication needs no second step and meets this organization's two-step requirement for that session.
- SCIM provisioning: Create SCIM Token, then enter the base URL and the token in the provider's provisioning settings. The provider creates and updates accounts in the verified domains. Deactivating a user removes them from the organization, disables the account, signs it out and ends its API tokens and connected apps. Group push is not supported; map groups to roles under Attributes and roles.
- Sign-in from the provider's portal (IdP-initiated) is off by default. Turn it on under Identity provider when members start from the provider's app dashboard.
Tips
- Every change to these settings is emailed to all org admins and recorded in the audit log.
- Test with one member before requiring single sign-on.
- When the provider's certificate changes, paste the new one next to the old one, save, and remove the old one after the switch.
Related
Organization Settings · Your Account · API and AI Tools (MCP)
Full documentation: Single Sign-On and SCIM › How to use it