Custom SAML SSO setup
Use this page when your IT team is connecting a SAML 2.0-compatible identity provider to Artifactive. Your Artifactive dashboard shows the setup values for your tenant, and we can help if your team wants an assisted setup.
How setup works
- Artifactive provides service-provider values in the dashboard.
- Your IdP admin creates a SAML 2.0 application.
- Your IdP admin enters the Artifactive ACS URL and Entity ID.
- Your IdP admin configures Name ID or the equivalent user identifier as the user's work email.
- Your IdP admin assigns the users, groups, or organizational units that should have access.
- Artifactive records the identity-provider metadata.
- An Owner runs Test SSO in Artifactive before enabling SSO-only access.
Values from Artifactive
| Value | How it is used |
|---|---|
| ACS URL / Reply URL / Single sign-on URL | Paste this into your IdP as the destination for SAML responses. |
| Entity ID / Audience URI / Identifier | Paste this into your IdP as the service provider identifier or audience. |
| Name ID format | Use email address if your IdP asks. |
| Start URL / RelayState | Leave blank unless Artifactive provides one. |
Values from your identity provider
- Metadata URL or metadata XML, preferred.
- IdP Entity ID / Issuer.
- SSO URL.
- x.509 signing certificate.
- Assigned users, groups, or organizational units.
Custom IdP notes
- Use the Artifactive ACS URL as the assertion consumer or reply URL.
- Use the Artifactive Entity ID as the service provider identifier or audience.
- Send the user's work email as Name ID or an equivalent email attribute.
- Leave Start URL or RelayState blank unless Artifactive provides one.
- Assign the users, groups, or organizational units that should open Artifactive dashboards.
Testing before enforcement
- Run Test SSO from Artifactive.
- Test with an assigned user on an approved company email domain.
- Do not switch to SSO-only until the test passes.
- For team SSO-only, confirm Owner access and recovery before enforcing it.
Common setup issues
- User is not assigned to the SAML app.
- ACS URL or Entity ID does not exactly match.
- NameID/email is missing or not the user's work email.
- Metadata or signing certificate changed after setup.