Task · Team
Require single sign-on
Turn on SAML single sign-on so your team signs in through your own identity provider.
5 steps · About 10 minutes · Needs: A SAML identity provider, and someone who administers it
-
Open Account settings then Team
Your accountSettingsgo.tito.io/acme/admin/settings -
Under Sign-in policy, choose your identity provider's metadata XML and select Upload metadata
Tito stores the configuration and leaves sign-in as it is.
-
Send SP metadata for your IdP admin to whoever administers your identity provider
That link is what they need to add Tito at their end.
-
Select Test sign-in through your organization
You come back with the configuration marked as verified. Activation only works from a session that has done this.
-
Select Activate SAML requirement, then confirm
Everyone on the team signs in through your identity provider from that moment. Email-link sign-in stops working for this account.
A replacement file that doesn't match your identity provider locks everyone out, including you.You can't reach Deactivate SAML requirement to undo it, so contact Tito support.
Replacing the metadata later
Once the requirement is on, Replace metadata loads a new file from your identity provider, usually when its signing certificate is about to expire.
Choosing a file doesn't change anything yet. Tito reads it and shows you the identity provider, the sign-in address and the certificate expiry date it contains, next to the ones in use. A certificate renewal shows No change on everything except the expiry date. Anything else changing means you have the wrong file.
Confirming switches everyone to the new configuration.
You can avoid the risk entirely. Select Deactivate SAML requirement first, replace the metadata while everyone can still sign in with an email link, run Test sign-in through your organization, then require single sign-on again.
The configuration stays, so you can turn the requirement on again after a fresh test sign-in.