Single sign-on
Acme supports SAML 2.0 and OpenID Connect (OIDC). You need admin access to your identity provider (IdP), such as Microsoft Entra ID or Okta.
Configure SSO
Section titled “Configure SSO”-
In the portal, go to Settings > Single sign-on and select your protocol.
-
Copy the values Acme shows you into your IdP:
Field in your IdP Value Entity ID urn:acme-service:<your-organisation-id>Reply URL (ACS) https://portal.acme-service.example/sso/saml/<your-organisation-id>/acsName ID format Email address Field in your IdP Value Redirect URI https://portal.acme-service.example/sso/oidc/callbackScopes openid,profile,email -
Copy the details from your IdP back into the portal: the metadata URL for SAML, or the issuer URL, client ID and client secret for OIDC.
-
Select Test sign-in. Sign in with a test user in a private browser window.
-
Select Enable. Users with your email domain now sign in through your IdP.
Your organisation ID is shown at the top of the Settings page.
Default role for new users
Section titled “Default role for new users”Choose the role given to people who sign in through SSO for the first time. We recommend Viewer, then raise access as needed in Users and roles.