Set up single sign-on with SAML 2.0
Tabs
FormCan works with any identity provider that supports SAML 2.0, for example OneLogin, JumpCloud, Ping Identity, Keycloak or ADFS. Use this guide when your provider has no guide of its own.
For an overview of the Single Sign-On page, see Single sign-on (SSO). There are separate guides for Okta, Microsoft Entra ID and Google Workspace.
Before you begin
- You can create a SAML application at your identity provider.
- In FormCan, you are the team owner or a member with the Manage members access.
- In FormCan, open your team menu and select Single Sign-On. On the Connection tab, pick Other (SAML).
Values for your identity provider
Create a SAML 2.0 application at your provider and enter the values from 2. Values for your identity provider:
- ACS URL: where your provider posts the SAML response. Other names: single sign-on URL, reply URL, assertion consumer service URL. The binding is HTTP-POST.
- Entity ID: the audience of the response. Other names: audience URI, identifier, SP entity ID. The same address serves the FormCan metadata, which many providers can import instead of typing the values.
- Start URL: optional. Use it as the login URL of the application tile.
Set the Name ID to the user’s email address, in the email address format.
Add three attributes to the response:
| Attribute | Value |
|---|---|
email |
The user’s email address |
firstName |
The user’s first name |
lastName |
The user’s last name |
If your provider uses other attribute names, keep them and enter those names under Advanced: attribute names in FormCan. When no email attribute is sent, FormCan uses the Name ID.
Values from your identity provider
Under 3. Values from your identity provider, either load the values or paste them:
- Load them: paste your provider’s Metadata URL and click Load from metadata.
- Paste them: enter the Identity provider entity ID (issuer), the Sign-on URL (HTTP-Redirect) and the Signing certificate (PEM or base64).
Click Save connection.
Verify your domain, test and turn on
-
On the Email domains tab, add your company domain, create the TXT record FormCan shows at your DNS provider, and click Verify.
-
In the status card, click Test connection. A window signs you in through your provider and shows the email, name and attribute names FormCan received. Use those names to correct the mapping if the name or email is missing.
-
Click Turn on single sign-on.
See Sign-in rules to require single sign-on or to let new members join automatically.
Technical details
- Sign-in can start at FormCan (SP-initiated) or at your provider (IdP-initiated).
- FormCan sends unsigned authentication requests over HTTP-Redirect. The assertion in the response must be signed.
- Responses are checked for signature, audience, destination, validity period and replay.
- Two signing certificates can be saved at the same time, so you can rotate a certificate without downtime.
- The sign-on URL and the metadata URL must be public
httpsaddresses. - Single logout is not supported. Signing out of FormCan does not sign the user out of your provider.
Troubleshooting
| Message | What to check |
|---|---|
| “The identity provider response was rejected: Invalid audience” | The Entity ID at your provider differs from the one on the FormCan page. |
| “The identity provider response was rejected: Signature validation failed” | The signing certificate changed. Load the metadata again or paste the new certificate below the old one. |
| “The identity provider did not send an email address.” | Send the email as the Name ID or as an attribute, and check the attribute name under Advanced: attribute names. |
| “The identity provider sent an email at @example.com, which is not one of your verified domains.” | The account’s email is on a domain you have not verified. |