1. Docs
  2. Single Sign-On
  3. Add an SSO connection

Add an SSO connection

Create an admin or end-user SSO connection in the Developer Console, paste the service-provider details into your identity provider, save its configuration, then activate it.

Create the connection

In the Developer Console, Tenant → Single Sign-On lists the Account's connections. Two kinds exist: admin SSO signs your own team in to Canopy, routed by the domains you verify on the Domains page; end-user SSO signs your application's users in, bound to an Environment. Single sign-on is a Pro feature; on a Free account the page says so and offers no create button.

Application
Developer Console
Path
TenantSingle Sign-On
Opens with
  • sso.view Read SSO connections, verified domains, the custom auth domain, and directory sync.
Context
Account-wide. No Application or Environment selection applies.
Create the connection
Open Single Sign-On from the left nav under Tenant. With nothing configured the page reads No SSO connections yet and offers Add admin SSO and Add end-user SSO.Click one. In Add admin SSO connection or Add end-user SSO connection, name the connection, choose the protocol, SAML or OIDC, and click Create connection. An SSO connection created. toast appears and you land on the connection's page with status Configuring.Read the Service provider details card: the ACS URL and the SP entity ID or metadata URL, generated by Canopy, to paste into your identity provider. A banner reads Not ready to activate and lists what is Still needed.

Configure, activate, disable, delete

The connection page holds the identity-provider side of the exchange, the Environment bindings for end-user SSO, and the email domains for admin SSO.

Configure, activate, disable, delete
Fill in Identity provider configuration from your IdP: its entity ID or issuer, its sign-in URL, and its signing certificate. Click Save configuration; a Configuration saved. toast appears and the banner clears.For end-user SSO, bind the Environments the connection serves under Environment bindings with Bind an Environment, choosing a default role and placement node for people it provisions. For admin SSO, add the verified Email domains it routes.Click Activate. A Connection activated. toast appears and the status becomes Active. Disable pauses it with a Connection disabled. toast.Delete the connection and confirm. The confirmation warns that people routed through it can no longer sign in via SSO and that this cannot be undone. A Connection deleted. toast appears.
If you don't see this

Each control on this page exists only for someone who may use it. When something described above is missing, one of these is why:

Single Sign-On is not in the left nav. Your administrator role does not carry sso.view.The page shows connections but no Add admin SSO, Add end-user SSO, Save configuration, or Activate. You hold sso.view but not sso.manage.The page says single sign-on is a Pro feature. The Account is on the Free plan; upgrade from the Admin Workspace's Billing page.Activate stays refused. The Still needed list names what is missing; admin SSO also needs a verified domain.
Environment
API version
v1.0
On this page Was this page helpful?

Tell us how we can improve this guide.