Single sign-on (SSO)
Connect your identity provider so your team signs in with the credentials they already use.
How it works
Veridenti federates to your IdP over SAML 2.0 or OIDC. When a user signs in, your IdP asserts their identity; Veridenti maps them to your tenant by verified domain and applies their role. No separate Veridenti password exists.
Setup
- In the admin console, open SSO & Directory.
- Choose your provider and follow the connection steps (you'll exchange metadata / a redirect URL and an ACS URL with your IdP).
- Verify your domain(s).
- Do a test sign-in from an incognito window before rolling out.
Requirements
- A SAML 2.0 or OIDC application in your IdP.
- Permission to add an enterprise app and (optionally) configure SCIM.
What if…
- A user can't sign in after SSO is on — confirm their email domain is verified and they exist in your IdP's assigned users/groups.
- You're locked out — your original one-time bootstrap link still works until it expires; ask Veridenti to reissue it if needed.
- You see "no SSO tax" — correct: SSO and SCIM are included at every tier, not a paid add-on.
Was this helpful?