Skip to main content

Single Sign-On (SSO)

Instructions for configuring Single Sign-on for your organization.

Written by Melinda Sather

Single Sign-On (SSO) allows members of your organization to access Paladin using a third-party identity provider (IdP). With SSO enabled, users can log in to Paladin using the same credentials they use for other services within your organization.

Without SSO, users must create and manage a separate password for Paladin. Enabling SSO provides a more secure and streamlined experience, as users do not need to maintain additional credentials. This enables your organization to centrally manage Paladin access.


SAML 2.0 Identity Providers

Paladin supports integration with any identity provider that uses the SAML 2.0 protocol. To configure a SAML integration, the following information is required:

Required Information

  • Paladin SAML Metadata (Production):
    https://app.joinpaladin.com/account/saml/metadata/

  • Paladin will provide a RelayState value, which must be included in your identity provider’s SAML response.

  • Once your identity provider is configured with the above information, your team will need to provide Paladin with your identity provider’s SAML metadata.

Our team will work with your IT/IAM team during onboarding to complete the SAML configuration.


Supported Providers

Okta SSO Instructions

If your organization uses Okta, you can configure both SSO and SCIM user provisioning.


Microsoft Entra ID (Azure AD) SSO Instructions

If your organization uses Microsoft Entra ID (Azure AD), you can configure both SSO and user provisioning.

Did this answer your question?