Supported SSO Providers
We support any SSO provider that conforms to a SAML 2.0-based protocol, such as Azure, Okta, or OneLogin. With SAML-based single sign-on, users can access Picflow through an identity provider (IdP) of their choice.
Available for: Enterprise Plan
βRequired role: Owner and Admin
How SAML 2.0 SSO Works
- Auth Request: When a Picflow user tries to log in using SSO, Picflow sends a SAML request to the identity provider (IdP). 
- Validation & Response: The IdP validates the user's credentials and sends a SAML response back to Picflow to confirm the user's identity. 
- Access Granted: Picflow acknowledges the response and grants access. 
How to set up SSO
Setting up SSO involves configuring your identity provider and Picflow to communicate securely. This process requires collaboration between your IT team and Picflow to exchange necessary information like SSO URLs, Entity IDs, and certificates.
- Contact Picflow: Please submit an SSO Request to express your interest. 
- Exchange Details: Exchange of configuration details between your IdP and Picflow: 
- Create SAML App: In your IdP's console, add Picflow as a new SAML app. 
- Provide Details: Submit your IdP details such as SSO URL, Entity ID, and the certificate through a secure channel. 
- Testing: We'll verify that the setup and all attributes are mapped correctly. 
- Roll Out: Notify users about the new SSO login method. 
