How to connect SAML SSO
How to connect SAML SSO
In this article:
- Overview
- Before you start
- Configure SAML SSO in SuperPath
- Test the connection
- Things to keep in mind
- FAQs
- Who can do this
Overview
Connecting SAML single sign-on (SSO) lets your team access SuperPath through your organisation's own identity provider. It simplifies signing in, improves security, and gives you more control over who can access your account. You configure it from the Custom SSO section on Settings → Security.
Before you start
Make sure that:
- Custom authentication has been enabled for your SuperPath account. This is switched on by SuperPath, so if you don't see the Custom SSO section, contact your account manager or SuperPath Support.
- You have confirmation from your SuperPath account manager that your account is ready for SSO.
- You have access to your SAML identity provider (for example sso.tools, Okta or Microsoft Entra ID) so you can copy across the connection details.
- You are signed in with an email address on the domain you want to use for SSO — the SSO Email Domain you enter must match your own email domain.
Configure SAML SSO in SuperPath
- Sign in to SuperPath as an Owner or Admin.
- Go to Settings → Security.
- Scroll to the Custom SSO section and click Configure SSO SAML.
- In the Setup SAML SSO panel, enter the details below, then click Save changes.
The panel has two kinds of field: values you copy from your identity provider into SuperPath, and read-only values SuperPath generates for you to paste into your identity provider.
Field | What it is |
|---|---|
SSO Email Domain | Your organisation's email domain (for example acmecorp.com). You must be signed in with an email on this domain to configure SSO. |
Entity Id | A unique identifier for your identity provider (IdP). It tells SuperPath who is authenticating the user and must exactly match the identifier configured in your IdP. |
SSO URL | The login endpoint for your identity provider. This is where SuperPath redirects users to authenticate; after a successful sign-in the user is redirected back to SuperPath with a valid SAML response. |
Certificate | The full signing certificate from your IdP, including the |
Service Provider Entity Id | Generated by SuperPath (read-only) — copy it into your identity provider. It is your SuperPath app URL: https://app.superpath.io (US) or https://app-au.superpath.io (AU). |
Authorization Callback URL | Generated by SuperPath (read-only) — copy it into your identity provider as the SAML assertion consumer (callback) URL. |
Test the connection
SuperPath supports one authentication method per user, so test carefully before moving everyone across.
Option 1 — test with a new user (recommended)
- Add a new user in your People list.
- Give them an email on your SSO domain (for example user@acmecorp.com).
- Set their login type to Custom SSO (SAML) and create the user.
- Ask them to sign in: at the SuperPath sign-in page they enter their SSO-domain email, are redirected to your identity provider to authenticate, and are returned to SuperPath once they succeed.
Option 2 — ask SuperPath for help
If you're unsure, contact the SuperPath Support team and we can help you test the connection safely.
Things to keep in mind
- Users whose email matches your SSO domain must sign in with SSO — password sign-in is disabled for them.
- Users on other email domains can still sign in with their existing method.
- To require SSO (or any specific method) for everyone, use the Enforce authentication type setting on Settings → Security. See How to enforce a login authentication type.
- Make sure each user exists both in your SAML provider and in SuperPath, as required by your setup.
- To change or remove a connection later, see How to edit or delete your SAML SSO configuration; to move existing people across in bulk, see How to migrate users to SAML authentication.
FAQs
Sign-in isn't working after I saved the configuration. What should I check?
Double-check the certificate formatting (including the BEGIN and END lines), confirm the Entity Id and SSO URL match your identity provider exactly, make sure the user exists in your identity provider, and verify their email domain matches the SSO Email Domain you configured.
Why must the SSO Email Domain match my own email?
SuperPath checks that the domain you enter matches the email you're signed in with, so you can't accidentally lock your account to a domain you don't control.
Can some people keep using email and password?
Yes. Only users whose email matches the SSO domain are required to use SSO. People on other domains keep their existing sign-in method unless you enforce a specific authentication type for everyone.
Who can do this
Only Owners and Admins can open Settings and configure Custom SSO — the whole /settings area is restricted to these two roles, so Managers, People Managers, Content Managers, Instructors, Employees and Restricted users cannot reach it. Custom authentication must also be enabled for your account by SuperPath before the Custom SSO section appears.
Updated on: 24/07/2026
Thank you!
