Single sign-on (SSO) with SAML or OIDC
Set up single sign-on for your analytics workspace with SAML 2.0 or OpenID Connect: IdP values, email domains, just-in-time provisioning and enforcing SSO.
SSO is available on the Business plan. Members sign in through your identity provider (IdP), so you control access centrally.
Values for your identity provider#
Replace ws_… with your workspace id (Workspace settings → Overview).
SAML 2.0#
| Setting | Value |
|---|---|
| ACS (reply / single sign-on) URL | https://privatusanalytics.com/users/auth/saml/callback |
| SP entity ID (audience) | https://privatusanalytics.com/users/auth/saml/metadata?workspace=ws_… |
| Name ID format | emailAddress |
| Name ID value | The user's email address |
| Attributes (optional) | name or displayName for the member's name |
From the IdP, you'll need its SSO URL, entity ID (issuer) and X.509 signing certificate, or its metadata XML to import.
OpenID Connect#
| Setting | Value |
|---|---|
| Redirect (callback) URI | https://privatusanalytics.com/users/auth/openid_connect/callback |
| Scopes | openid email profile |
| Flow | Authorization code with PKCE |
From the IdP, you'll need the issuer URL (we use its discovery document), a client id and a client secret.
Set up#
- Workspace settings → SSO. Choose SAML or OIDC and enter the IdP's values.
- List your email domains. Only people with those domains can sign in through SSO.
- Choose just-in-time provisioning and the default role for new members (any role except Owner).
- Test: sign in through the IdP in a private window. A successful test marks the configuration as tested. Nothing changes for other members.
- Activate. Members can now use Log in with SSO (enter your email or domain).
- Optional: Enforce SSO, so members of this workspace must sign in through the IdP. Keep one owner with another sign-in method as a break-glass account.
Signing in#
On the login page choose Log in with SSO and enter your work email. You are sent to your IdP and back. Start sign-in from Privatus Analytics (SP-initiated). Tiles in your IdP's app dashboard should link to the Privatus Analytics SSO login page.
Guides#
Okta · Microsoft Entra ID · Google Workspace · JumpCloud. To create and remove members automatically, add SCIM.