Authentication & Access

Single Sign-On (SSO)

Single Sign-On (SSO)

Overview

Connetra supports Single Sign-On (SSO) via SAML, enabling seamless and secure access to your workspaces. By integrating with Identity Providers (IdP) such as Google, Azure AD, Okta, and Auth0, Workspace Owners can centralize authentication, improve security, and simplify user management.

Configuring SSO in Connetra

To set up SSO for your workspace, follow these steps:

  • Navigate to your Workspace Settings and select the SSO tab.
  • Choose your SAML Identity Provider from the available options (e.g., Google, Azure AD, Okta, Auth0).
  • You will be provided with Connetra's Service Metadata:
    • Identifier (Entity ID): The URL used to identify Connetra to your IdP.
    • Reply URL (ACS URL): The destination where the IdP will send the SAML assertion.
    • Logout URL: The URL used for Single Logout (SLO).
  • Configure your Identity Provider using the provided Service Metadata.
  • Once configured on the IdP side, enter the IdP details into Connetra. You can either manually input the SSO URL, Logout URL, and Certificate, or automatically import them by uploading your IdP's XML Metadata file.
  • Save the configuration and enable Active SAML.

Enforcing SSO

Once SSO is successfully configured and tested, Workspace Owners can toggle the Enforce SSO option. When enforced, all users belonging to this workspace will be required to authenticate via the configured Identity Provider. They will no longer be able to log in using their standard email and password.

Logging In with SSO

When users navigate to the Connetra login page and enter their email address, the system automatically detects if their primary workspace has SSO enabled.

  • If SSO is available but not enforced, users will see an option to log in via "Single Sign-On (SSO)" alongside the standard password login.
  • If SSO is enforced, users will automatically be redirected to the Identity Provider's login page to authenticate.

Disabling or Resetting SSO

Workspace Owners can disable or delete the SSO configuration from the Workspace Settings at any time. If SSO is disabled, members will revert to using their standard email and password for authentication.