# Setting up SAML SSO

Last updated 9 days ago

### Who can use this feature

- Supported on **Team** and **Enterprise** plans
- Note: **Team** plans are limited to Okta and Google SAML only
- Anyone with an org admin or IT admin role can access and edit SSO

In this article, we'll show you how to set up single sign-on, so users can authenticate into WRITER easily. If you're looking for information about automatically provisioning new users, check out our article, [Setting up SCIM provisioning](https://support.writer.com/article/88-setting-up-scim-provisioning#Step-by-step-configuration-instructions-iJSb-).

## Configuring single sign-on

Start by navigating to **Admin > Access & provisioning** then selecting the **SSO** tab. Select **Set up single sign-on**.

Before you can set up single sign-on, you'll need to claim your domain. To do so, select **Claim domain**. Learn more about claiming a domain [here](https://support.writer.com/article/288-setting-up-domain-access).

### Configuring domain access before setting up single sign-on

We **strongly** recommend the following configuration choices:

- Enable domain discoverability _before_ you continue setting up single sign-on.
- Keep the ability to create passwords turned _on_ until you've fully tested your SSO configuration.

These two steps will prevent users from being locked out of WRITER while you're troubleshooting your single sign-on configuration.

Once you've successfully launched and tested single sign-on, you can turn off password creation if you wish.

Next, you'll switch back and forth between WRITER and your identity provider (IdP) to share information between the two systems.

### Select your IdP (identity provider)

Give your SSO connection a **Name** to identify it easily.

WRITER actively supports single sign-on with multiple providers specified on this page. However, you can also set up single sign-on with other identity providers as well. If you’re using another identity provider, select **Other IdPs**. Then scroll down to complete the connection.

### Share information from WRITER with your identity provider (IdP)

If you look at Box A, you’ll see 2 fields that you’ll need to paste into your IdP ( _SP SSO URL_ and _SP Entity ID_).

**Note:** Identity providers sometimes use different terminology for these fields

1. _SP SSO URL_ is sometimes known as _ACS (Assertion Consumer Service) URL_ or _Recipient_
2. _SP Entity ID_ is sometimes known as an _Audience URL._

Some IdPs may ask you to upload a metadata XML file from WRITER to your IdP. This is rare, but if you need this, select **Download SP Metadata XML**. You can then upload this into your IdP.

### Share information from your identity provider with WRITER

Go to the WRITER SSO application in your identity provider to retrieve a SAML metadata XML. This process differs depending on your IdP. Below are some guides for our most popular IdPs:

- [Setting up Entra SSO](https://support.writer.com/article/274-setting-up-entra-sso)
- [Setting up PingOne SSO](https://support.writer.com/article/278-setting-up-pingone-sso)
- [Setting up PingFederate SSO](https://support.writer.com/article/280-setting-up-pingfederate-sso)
- [Setting up Okta SSO](https://support.writer.com/article/273-setting-up-okta-sso)

Almost all IdPs will provide a SAML metadata XML. This is required from WRITER to complete configuration. Once you have the XML from your IdP, upload it in Section B. We’ll analyze this XML and auto-populate the _IdP Issuer_ and _IdP SSO URL_ fields.

Once we have your IdP’s XML uploaded, you can select **Finish** to finish setup.

## Single sign-on settings

When you navigate to **Admin settings > Access & provisioning** and select the **SSO** tab, you should see your new SSO identity provider at the top of the page.

To edit your configuration settings, select the settings icon in the top right.

To delete your SSO configuration, select the trash can.

### Set up SCIM provisioning

Once your SSO configuration is complete, you can provision users directly from your IdP by setting up a SCIM (System for Cross-domain Identity Management) connection. Learn more in our Help Center article [Setting up SCIM provisioning](https://support.writer.com/article/88-setting-up-scim-provisioning).

## Frequently asked questions

### General

**Q: Do I need to do anything in the IdP before my users are able to sign on via SAML?**
Make sure to assign users to the app in your IdP before they can sign on via SAML.

**Q: Do you support configurable session timeouts from the IdP?**
No, we do not support configurable session timeouts.

**Q: How do I switch identity providers?**
Select the trash can icon to remove your SSO configuration and repeat the process with your new IdP.

**Q: What role/access will new users have when added via SAML?**
They will have the default role as specified in **Admin > Access & provisioning** under the **Domain access** tab. Learn more [here](https://support.writer.com/article/288-setting-up-domain-access).

**Q: Does your application support SAML 2.0 authentication?**
Yes.

**Q: Does your application support OIDC authentication?**
No.

**Q: Does your application provide SAML SP metadata?**
Yes, under **Admin > Access & provisioning** under the **SSO** tab.

Once you've selected an identity provider, select **Download SP Metadata XML**.

**Q: What is the SAML Single Sign On URL (ACS URL, Recipient)?**
```plaintext
https://app.writer.com/api/access/saml
```

**Q: What is the SAML SP Entity ID (Audience)?**
This is found at **Admin > Access & provisioning** under the **SSO** tab, once an identity provider is selected. For most accounts, this will be [_app.writer.com_](http://app.writer.com/) though some accounts may see _app.writer.com/api/access/saml_.

**Q: What SAML binding do you support?**
HTTP POST

**Q: What is the default SAML relay state?**
We don't enforce a default value. This can be empty.

**Q: What SAML NameID formats do you support?**
_emailAddress_ or any other format if the _email_ profile attribute is defined.

**Q: What Identity Providers have you previously integrated with successfully?**
Azure, GSuite, Okta, OneLogin, PingIdentity.

**Q: What additional profile attributes, if any, are you expecting in the assertion/claim from SAML IdP?**
_first\_name_, _family\_name_, _picture\_url_

**Q: Do you require encrypted assertions?**
No.

**Q: Do you require encrypted name identifiers?**
No.

**Q: Do you support Service Provider Initiated SSO, Identity Provider Initiated SSO, or both?**
Both.

**Q: Do you support "deep linking" and if yes, how do you offer this?**
No.

**Q: Do you support JIT or OOB user provisioning?**
Both.

**Q: If OOB user provisioning is required, what methods do you support?**
SCIM. Learn more about setting up SCIM provisioning [here](https://support.writer.com/article/88-setting-up-scim-provisioning).

**Q: Do you have a non-prod environment we could connect to?**
No.

**Q: Can the application be configured to remove users who have not logged in for a specific period of time?**
No.

### Error messages

**Q: When I add my email domain and select Next, I’m getting an error that says “One or more of the domains you added are already registered by another organization.”**
Email domains that you add to single sign-on have to be completely unique. It’s possible that someone else from your organization has already set up another WRITER account. To resolve this, email [support@writer.com](https://support.writer.com/articles/support@writer.com) and we’ll help you sort it out.

**Q: When I add my IdP metadata XML and select done, I’m getting an error that says “Your IdP configuration failed: Identity provider with same entity id is already registered!”**
Your IdP metadata has to be completely unique. It’s possible that someone else from your organization has already set up another WRITER account. To resolve this, email [support@writer.com](https://support.writer.com/articles/support@writer.com)

**Q: I got an email from WRITER saying that our _SSO certificate is about to expire_. Where do I upload a new certificate?**
Upload a new certificate by navigating to **Admin > Access & provisioning** and select the **SSO** tab. Follow the steps listed [here](https://support.writer.com/articles/9483481684-setting-up-saml-sso#Section-B-From-your-IdP-into-Writer--KZpf9).
