> For the complete documentation index, see [llms.txt](https://docs-vnext.kiflo.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs-vnext.kiflo.com/account-settings/users-security/how-to-setup-sso-single-sign-on.md).

# How to set up SSO (Single Sign-On)?

{% hint style="info" %}
The SSO option is only available on the **Premier** plan.
{% endhint %}

Enabling single sign-on allows you or your partners to access Kiflo without having to enter your password.

This is particularly useful if you provide many portals to partners, like an LMS, a ticketing system, or any other external application. Partners will seamlessly switch from your LMS to Kiflo or vice versa. **It greatly improves partners' experience.**

{% hint style="info" %}
**IN THIS ARTICLE**

[Overview](#overview)

[Enable single sign-on](#enable-single-sign-on)

[Set up your identity provider (generic instructions)](#set-up-your-identity-provider-generic-instructions)

[Set up your identity provider (Google, Microsoft)](#set-up-your-identity-provider-google)
{% endhint %}

## Overview <a href="#overview" id="overview"></a>

Kiflo implements SAML 2.0 and acts as the service provider. It is possible to enable or enforce the usage of SSO for admins and/or partners independently.

However:

## Enable single sign-on <a href="#enable-single-sign-on" id="enable-single-sign-on"></a>

To enable SSO:

* Navigate to the **Account Settings** page from the tom-right menu
* Then click on **Security**
* Toggle on **Single Sign-On (SSO)**

![](https://3041514930-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FKkJn82Qo5a0Y4fOsoQzo%2Fuploads%2Fgit-blob-e380421e4ebead83c268a9c47038befe1f70461e%2F698f1a2bacde8d0d4ee337e8.png?alt=media)

Then, you must choose whether your coworkers and partners can use SSO:

* **Disable**: They cannot sign-in via SSO and must use their password
* **Enable**: They can choose to sign-in via SSO as well as password
* **Enforce**: They must use SSO to sign-in and their password is disabled

Finally, fill in the **Identity Provider Login URL** and **Certificate** based on the information provided by your IP.

## Set up your identity provider (generic instructions) <a href="#set-up-your-identity-provider-generic-instructions" id="set-up-your-identity-provider-generic-instructions"></a>

Your Identity Provider will ask for a **callback URL** (where the SAML token will be sent). This callback URL is generated by Kiflo.

* Navigate to the **Account** page
* Then click on **Security**
* Copy the value of "**Service Provider Callback URL**"

![](https://3041514930-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FKkJn82Qo5a0Y4fOsoQzo%2Fuploads%2Fgit-blob-e8a89d35281490a81280aeb7f07c880aa845c457%2F688b7e14d77b850c2bba960a.png?alt=media)

### SAML attribute mapping

Set up attribute mapping to map the primary email address to the attribute **NameID**.

This is the only attribute required by Kiflo.

{% hint style="warning" %}
The primary email address registered in your IdP must be the one used in Kiflo to sign in.
{% endhint %}

## Set up your identity provider (Google) <a href="#set-up-your-identity-provider-google" id="set-up-your-identity-provider-google"></a>

**Google Workspace**

[How to set up SSO with Google?](/account-settings/users-security/how-to-set-up-sso-with-google.md)

**Microsoft Entra ID**

[How to set up SSO with Microsoft Entra ID?](/account-settings/users-security/how-to-set-up-sso-with-microsoft-entra-id.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs-vnext.kiflo.com/account-settings/users-security/how-to-setup-sso-single-sign-on.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
