Skip to main content
Account settings, security & privacy

Set up SSO

Connect fynk with Microsoft Entra ID, Okta or Google via SAML so your team logs in with their company account.

Written By Sebastian

Last updated About 13 hours ago

With single sign-on (SSO), your team logs in to fynk with their company account. fynk supports SAML 2.0 with identity providers such as Microsoft Entra ID, Okta and Google.

Available on Pro · Owner and Admin

Before you start

  • You need the Pro plan. Contact us to activate SSO for your account.
  • You need admin access to your identity provider.
  • SSO handles login only. To create and remove users automatically, also set up SCIM. See Provision users with SCIM.

Set up SSO

  1. In fynk, go to Account settings → Integrations → SAML.
  2. Copy the ACS URL and the SP Entity ID.
  3. In your identity provider, create a new custom SAML application and paste these values.
  4. Map the NameID to the user's email address.
  5. Assign the users or groups who should use fynk to the application.
  6. Copy the identity provider's metadata URL, paste it into the SAML settings in fynk and save.

Setup in Microsoft Entra ID

  1. In Entra ID, go to Enterprise applications → New application → Create your own application and choose a non-gallery application.
  2. Open Single sign-on and choose SAML.
  3. Paste the fynk ACS URL into Reply URL and the SP Entity ID into Identifier (Entity ID).
  4. Copy the App Federation Metadata URL into the SAML settings in fynk.

Setup in Okta

  1. In Okta, create a new app integration and choose SAML 2.0.
  2. Paste the fynk ACS URL into Single sign-on URL and the SP Entity ID into Audience URI (SP Entity ID).
  3. Set the Name ID format to EmailAddress.
  4. Copy the app's metadata URL into the SAML settings in fynk.

Log in with SSO

Users log in at https://app.fynk.com/sso/login. The email address in your identity provider must match the user's email address in fynk.

Enforce SSO

Once SSO works, you can make it mandatory for everyone. To turn on Enforce SSO, you must be logged in via SSO yourself and have the Owner or Admin role.

Troubleshooting

  • User can't log in: check that the user is assigned to the application in your identity provider.
  • Keycloak: remove the "role_list" client scope.

Good to know

  • Use the identity provider's metadata URL rather than uploading metadata by hand. fynk then keeps the metadata in sync, so you never have to replace the certificate yourself. Click the refresh button next to the metadata URL before you save.
  • If your identity provider admin has no fynk account, an Owner or Admin can invite them as Admin for the setup and remove them afterwards.
  • With SSO enforced, you can use your identity provider to control which users, devices and networks can log in to fynk.
  • When SSO is enforced, you can't exclude individual users or domains.
  • Don't combine SSO with 2FA in fynk. Use your identity provider's multi-factor authentication.
  • Existing passwords remain if you turn SSO off again.