Skip to main content

General SSO (Single Sign-On) set up instructions

As a corporate administrator, you have the option to permit members of a corporate email to access Short.io without the need for registration. Through SSO (Single Sign-On), Short.io streamlines the identity verification process, enabling your Organization/Team members to log in without having to set up another password.

Short.io currently supports Google Workspace, Microsoft Azure Active Directory services**, Broadcom SiteMinder, PingFederate, Office 365, OneLogin, Okta, Salesforce, SSOCircle** and other SAML providers.

Note

SSO is available on the Enterprise Plan.

SSO login video demo



Configuring Short.io SSO

Before you begin

You need to create and enable a SAML configuration in Short.io before setting up SSO with your idP provider.

Follow these steps:

  1. From Short.io's left panel, expand the Organizations settings.

  2. Click the icon next to the Organization where you want to configure SAML:

  3. Navigate to the SAML tab:

  4. Click Add SAML configuration.

  5. In the next screen:

    • set Config enabled

    • enter Your SSO configuration name (or your company name)

  6. Copy the ACS URL (this is where you go when trying to log in using SSO) and save it for later:

  7. Save.

idP configuration

Using a SAML provider supported by Short.io, you need to:

  1. Enter the following link where you substitute <yourcompanyname> with Your SSO configuration name:

    https://authorizer.short.io/auth/saml/<yourcompanyname>

    into the respective field of the provider's settings.

  2. Copy and save the following data: Identity Provider Single Sign-On URL (or similar name), Identity Provider Issuer (or similar name) and the X.509 certificate.

Short.io configuration

  1. Paste the copied values into the respective Short.io Organization SAML fields as follows:

    • Identity Provider Single Sign-On URL into the Entry point URL field

    • Identity Provider Issuer into the Service provider issuer field

    • X.509 certificate content into the Public certificate field

  2. Optionally, you can add members to sign in to a team using this SSO configuration. Expand the list and select one of the teams:

  3. Optionally, you can map SAML attributes in your identity provider to control how members are provisioned when they sign in. Here is the list of available settings:

  4. Expand the Advanced options where you can:

    • add an extra layer of security with Sign auth request enabled

    • specify which RequestedAuthContext Short.io should send in authentication requests to your identity provider (select one from the list) - Password, Kerberos, X.509, TLS or FederationAuthWindows

    • define whether the Response and Assertions should be signed

    • enable profile update each time users log in

    • allow users to choose their own display name

    • specify whether SSO is optional or is required for all members of the Organization:

  5. Save.

Note

The Short.io team configures SSO within 24 hours.

In case you need further assistance, please contact the Short.io support team at [email protected].

First-time logging in with SSO

With the SAML configuration set up, your Organization members can use the Short.io's ACS URL or the page https://app.short.io/public/login (button SSO) to log in.

Short.io automatically creates a SAML-based login in the given Organization with the role Member for each user who logs in via SSO for the first time:

In case you have added a user without specifying a team, the Organization admin(s) should grant this user access to the resources they are authorized to use:

Otherwise, when team members log in through SSO, they are redirected to the dashboards and settings they usually have permission to access.