← Back to Developer Portal

SSO Configuration

Enterprise Single Sign-On with SAML 2.0 and OIDC

Identity Provider Type

SAML 2.0 Configuration

Or configure manually:

TAB SP Metadata (give this to your IdP admin):

/api/sso/saml/metadata

Domain & User Provisioning

Only users with these email domains can authenticate via SSO. Leave empty to allow all.

Auto-provision users

Automatically create TAB accounts on first SSO login

Force SSO

Require SSO for all users (disables password login)

Group-to-Role Mapping

Map IdP group names to TAB roles. When a user authenticates, their IdP groups will be checked against this mapping.

Enable SSO

Activate SSO for your organization

Recent SSO Events

Loading...