Authentication
SSO discovery and redirects
SAML single sign-on, discovery by email domain, and SSO redirects.
SAML connections#
An organization in your environment can sign in through its own identity provider, such as Okta, Microsoft Entra ID or Google Workspace, over SAML 2.0. Set the connection up under the organization's SSO settings; the service provider URLs to give the identity provider are shown there:
- Metadata:
/sso/saml/:connectionId/metadata.xml - Assertion consumer service:
/sso/saml/acs/:connectionId. Both service-provider-started and identity-provider-started sign-ins are accepted.
Assertions must be signed. Audience, time window, request ID and replays are checked. Users are created on their first sign-in.
Discovery by email domain#
After the email step, the hosted sign-in asks GET /sso/saml/discover?email=…&environmentId=…. When the address's domain belongs to an organization with an active connection, the user is sent to their identity provider instead of the password step. The domain must be verified by the organization first.
Redirects#
GET /sso/saml/login/:connectionId starts a SAML sign-in directly, for “Sign in with SSO” buttons. The result comes back through the same one-time code handoff as every hosted sign-in.
On the 3een dashboard#
3een accounts use a separate discovery (GET /app/sso/discover?email=…). It answers 200 { mode: "password" } when no SSO applies, and never says whether the address has an account.