Skip to main content

Overview

SAML SSO lets your organization centrally manage authentication and user access. Once enabled, users will authenticate through your identity provider, such as Okta, Azure AD, OneLogin, Ping, or any SAML-compatible system. You’ll be asked to copy values from your identity provider (IdP) into Starbridge. After you save the configuration, Starbridge will display the remaining values you need to paste back into your IdP to complete the connection.
1

Choose your authentication mode

In Authentication Mode, choose how your users should authenticate going forward:
Users sign in using only their Starbridge password. SSO is disabled.
2

Enter your identity provider (IdP) details

Your IdP will provide two pieces of information that must be entered into Starbridge.Sign-in URLThis is your IdP’s SAML login endpoint (often called the “SSO URL,” “Login URL,” or “Identity Provider SSO URL”). Paste the full URL from your identity provider.X.509 certificatePaste the X.509 certificate provided by your IdP. This certificate is used to verify signed SAML responses returned by your identity provider.
Copy only the certificate text, including the ----BEGIN CERTIFICATE----- and ----END CERTIFICATE----- lines. If your IdP provides multiple certificates, use the active signing certificate.
3

Save your configuration

After pasting your Sign-in URL and X.509 certificate, click Save.If the settings validate successfully, Starbridge will display the remaining values your IdP needs to complete the SSO connection.
4

Copy Starbridge values back to your IdP

Starbridge will display your application-specific SAML details, including:
  • Domain
  • Entity ID
  • SSO URL
Copy these values into your identity provider’s SAML configuration, then follow your IdP’s prompts to finalize.
5

Test your SSO connection

Test logging in with SSO.
We strongly recommend testing before enforcing SSO for all users.

Need help?

If you need assistance configuring your identity provider or troubleshooting SSO, contact support@starbridge.ai and include:
  • Your IdP (Okta, Azure AD, etc.)
  • A screenshot of your SAML configuration
  • The error message seen during login (if any)