Configure Single Sign-On (SAML)
Connect your identity provider (Okta, Microsoft Entra ID, and others) so your team signs in with their existing company credentials.
Overview
SAML SSO lets your team sign in to ShipScience using your own identity provider (Okta, Microsoft Entra ID, and others), instead of a ShipScience password. Once set up, your IT team manages who has access from your identity provider directly.
What we need from you
- Your identity provider's SAML metadata: the metadata URL or the metadata XML file. If you cannot share metadata, send the Sign-in URL (also called SSO URL / Login URL) and the signing certificate (X.509, .pem or .cer).
- The email domain(s) your users sign in with (for example acme.com).
- Confirmation that each user's email address is included in the SAML response (as the NameID or as an attribute), plus the exact attribute names you send for email, first name, and last name if they are not the standard ones.
- One test user (email address) we can sign in with, and a time window for the switch. From that moment, everyone at your company signs in through your identity provider.
What to configure on your side
On your side, configure ShipScience in your identity provider with these values (we will confirm the exact connection name before you start):
- Assertion Consumer Service (ACS) / Reply URL / Single sign-on URL: https://login.shipscience.com/login/callback?connection=[your-company]-saml
- Entity ID / Audience URI: urn:auth0:shipscience-prod:[your-company]-saml
- SP metadata (if your identity provider can import it): https://login.shipscience.com/samlp/metadata?connection=[your-company]-saml
- NameID format: urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified (please use the user's email address, or another value that never changes for that user)
- Response binding: HTTP-POST to the ACS URL above. Our sign-in requests use HTTP-Redirect and are not signed.
- Sign-on / start URL for a bookmark or tile: https://app.shipscience.com/sign_in (users type their work email there and are sent to your identity provider). Please do not enable IdP-initiated sign-in for this application.
What happens at cutover
From the agreed cutover moment, everyone at your company signs in through your identity provider; ShipScience passwords and Google sign-in are no longer accepted for your account.
Support
ShipScience: [email protected]
Include your company name and the email address of the user affected.
Updated about 3 hours ago
