Single sign-on (SAML)
Let your team sign in to ABlyft through your company's identity provider using SAML.
With single sign-on (SSO), your team members sign in to ABlyft through your company's identity provider (IdP), for example the one that also manages your email and other business tools. ABlyft uses the SAML standard.
SSO is a feature of certain plans. If you do not see Single Sign-On in your team settings, it is not part of your plan. Contact ABlyft to find out more.
Who does what
Configuring SSO is reserved for owners, see Roles & permissions. Admins can only look at the status and download the ABlyft (service provider) metadata. Creating the ABlyft application in your identity provider is a task for your IT administrator.
Set up SSO
Open the user menu, click Team settings, then Single Sign-On.
Step 1: Register ABlyft in your identity provider
Your IT administrator creates a new SAML application for ABlyft in your identity provider. To make this easy, click Download SP metadata on the page. The XML file contains everything your provider needs to know about ABlyft: the entity ID, the endpoint that receives the sign-in response and the certificate. Import the file, or copy the values from it.
Requirements for your identity provider:
- The response from the provider must carry a signed assertion. ABlyft rejects unsigned assertions.
- ABlyft signs its own sign-in requests. The metadata file contains the certificate that your provider can use to verify them.
- ABlyft sends the user to the single sign-on URL of your provider using the HTTP redirect binding, and receives the response via HTTP POST.
- The name ID of a person must be stable and unique, because ABlyft uses it to recognize the person later.
Step 2: Enter your provider's details in ABlyft
-
Click Configure IdP.
-
Fill in the fields, or paste the IdP metadata URL (optional) and click the fetch button next to it to fill them automatically (HTTPS only):
Field Content IdP Entity ID The unique identifier of your identity provider IdP Single Sign-On URL The URL where ABlyft sends people to sign in IdP x509 Certificate The public certificate with which your provider signs its responses -
Save. ABlyft stores this as a draft and shows "Draft SAML configuration saved. Send a test login before activating."
At this point nothing changes for your team members.
Step 3: Send a test login
- Click Send test login. You are redirected to your identity provider.
- Sign in there. If it works, you return to ABlyft with the message "Test login succeeded."
If the test fails, check the draft details and try again.
Step 4: Activate
Activate is only available after a successful test of the current draft. If you change the draft afterwards, the test result is reset and you have to test again.
- Click Activate and read the confirmation. From now on every member, including you, must sign in with SAML SSO to access this team.
- Confirm. ABlyft redirects you to your identity provider one more time.
- After signing in, you see "SAML SSO is now active, and your account is linked."
Do not lock yourself out
Always run the test login first and keep the identity provider account of the owner working. Once SSO is active, members cannot enter the team without it.
Link your team members
ABlyft recognizes a person at the identity provider by their name ID, so each member's ABlyft account must be linked to their company identity once.
- Existing members: an owner opens Team settings → User Management, clicks Edit next to the member and then Send SAML link invite (or Resend SAML link invite). The member receives an email, follows the link and signs in at the identity provider. The link is valid for 7 days. The same dialog shows whether the member is already linked ("Linked to company SSO since …" or "Not linked to company SSO.").
- New members: when your team uses SSO, the invitation link leads to the identity provider. After signing in there, the person is added to your team with the invited role.
An owner can also use Remove SSO link in the same dialog. The person can then no longer sign in via SSO until they are linked again, and their active SSO session for the team ends immediately.
Signing in with SSO
On the ABlyft login page, enter your work email address and click Log in using SSO. ABlyft redirects you to your identity provider. If your company identity is not yet linked, you see "Your company identity is not linked to an ABlyft account yet. Ask a team owner to send you a link invite."
If every team of an account uses SSO, signing in with email and password is not possible for that account. An SSO sign-in stays valid for as long as your normal ABlyft session.
Deactivate or reactivate
An owner can click Deactivate to turn SSO off for the team. Members then use their normal sign-in again. Reactivate turns it on again, with the same requirement that the current draft has passed a test login.