Proof

Set up single sign-on in your Proof account – Proof Help Center

The Proof Help Center guide details setting up Single Sign-On (SSO) in a Proof account by verifying your domain, configuring SAML metadata from your identity provider either via an XML file or manual entry, and completing setup through the Command Center’s Security > Identity providers section, emphasizing that once activated by an admin, SSO affects all organizational users.

Overview

Single Sign-On (SSO) allows users to log in to multiple applications using a single set of credentials, with account and credential management handled by your identity provider (IDP), not by Proof.

Setting up SSO in Proof involves several steps:

  1. 1.Verify your domain.
  2. 2.Set up single sign-on in your Proof account.
  3. 3.Set up SAML configurations with your identity provider for SSO.

Note: Once SSO is configured by an owner or admin, all users in your organization are affected by the changes.


What You Need

Configuring SSO is bidirectional: the Service Provider (SP) metadata must be configured in the IDP, and the IDP metadata must be configured in the SP. You need both of the following:

  • A Proof-verified domain
  • A metadata file (.xml) from your identity provider

Metadata file options:

  • Option A (most common): Download a metadata file (.xml) from your Identity Provider (IDP).
  • Option B: If you cannot download a metadata file, you will need to manually gather:
    • Entity ID
    • X509 public certificate
    • Single sign-on (SSO) URL
    • SSO request binding
    • [Optional] Single log-out (SLO) URL and request binding

Set Up SSO

  1. 1.Click Security from the left menu in Command Center.
  2. 2.Select Identity providers.
  3. 3.Click Configure new identity provider in the upper right corner.
  4. 4.Type an internal name for your configuration.
  5. 5.Select a method for providing your metadata:
    • XML file: Upload the metadata file (.xml) from your IDP.
    • Manual entry: Provide the required fields from your IDP.
  6. 6.Click Process.
  7. 7.Review the configuration in detail:
    • Confirm at least one certificate is visible and in the Active state.
    • If an SLO URL is provided, SLO will be enabled.
    • You can delete and replace the metadata file or edit configuration details if needed.
  8. 8.Click Save.
    • The SAML configuration is not yet active at this stage.
  9. 9.Proceed to the next section to activate.

Activate Your SAML Configuration

To activate the SAML configuration, connect it to a verified domain:

  1. 1.Select Details and Policies for the domain you'd like to update.
  2. 2.Click Edit.
  3. 3.Select the configuration you created from the dropdown.
    • Review configuration details, including JIT provisioning, routing logic for new users, and whether users will retain password access.
  4. 4.Click Save.

Once saved, the SSO configuration will be live and applied to all users on the Proof platform with your domain.


Summary Checklist

  • Verify your domain in Command Center.
  • Obtain a metadata file (.xml) from your identity provider, or gather Entity ID, X509 certificate, and SSO URL.
  • In Command Center, go to Security → Identity providers and click Configure new identity provider.
  • Upload your metadata file or enter your IDP details manually, then click Process.
  • Review the certificate status and click Save.
  • Under Details and Policies for your domain, select the new configuration and save to activate SSO.

If you need further assistance, you can submit a support request or chat with the support team from any page in the app.