Set up single sign-on in your Proof account – Proof Help Center
The Proof Help Center guide details setting up Single Sign-On (SSO) in a Proof account by verifying your domain, configuring SAML metadata from your identity provider either via an XML file or manual entry, and completing setup through the Command Center’s Security > Identity providers section, emphasizing that once activated by an admin, SSO affects all organizational users.
Overview
Single Sign-On (SSO) allows users to log in to multiple applications using a single set of credentials, with account and credential management handled by your identity provider (IDP), not by Proof.
Setting up SSO in Proof involves several steps:
- 1.Verify your domain.
- 2.Set up single sign-on in your Proof account.
- 3.Set up SAML configurations with your identity provider for SSO.
Note: Once SSO is configured by an owner or admin, all users in your organization are affected by the changes.
What You Need
Configuring SSO is bidirectional: the Service Provider (SP) metadata must be configured in the IDP, and the IDP metadata must be configured in the SP. You need both of the following:
- A Proof-verified domain
- A metadata file (.xml) from your identity provider
Metadata file options:
- Option A (most common): Download a metadata file (.xml) from your Identity Provider (IDP).
- Option B: If you cannot download a metadata file, you will need to manually gather:
- Entity ID
- X509 public certificate
- Single sign-on (SSO) URL
- SSO request binding
- [Optional] Single log-out (SLO) URL and request binding
Set Up SSO
- 1.Click Security from the left menu in Command Center.
- 2.Select Identity providers.
- 3.Click Configure new identity provider in the upper right corner.
- 4.Type an internal name for your configuration.
- 5.Select a method for providing your metadata:
- XML file: Upload the metadata file (.xml) from your IDP.
- Manual entry: Provide the required fields from your IDP.
- 6.Click Process.
- 7.Review the configuration in detail:
- Confirm at least one certificate is visible and in the Active state.
- If an SLO URL is provided, SLO will be enabled.
- You can delete and replace the metadata file or edit configuration details if needed.
- 8.Click Save.
- The SAML configuration is not yet active at this stage.
- 9.Proceed to the next section to activate.
Activate Your SAML Configuration
To activate the SAML configuration, connect it to a verified domain:
- 1.Select Details and Policies for the domain you'd like to update.
- 2.Click Edit.
- 3.Select the configuration you created from the dropdown.
- Review configuration details, including JIT provisioning, routing logic for new users, and whether users will retain password access.
- 4.Click Save.
Once saved, the SSO configuration will be live and applied to all users on the Proof platform with your domain.
Summary Checklist
- Verify your domain in Command Center.
- Obtain a metadata file (.xml) from your identity provider, or gather Entity ID, X509 certificate, and SSO URL.
- In Command Center, go to Security → Identity providers and click Configure new identity provider.
- Upload your metadata file or enter your IDP details manually, then click Process.
- Review the certificate status and click Save.
- Under Details and Policies for your domain, select the new configuration and save to activate SSO.
If you need further assistance, you can submit a support request or chat with the support team from any page in the app.