Single sign-on
Learn how to set up SSO for your Attio workspace.
Single Sign-On (SSO) enables Enterprise workspaces to manage user access through their identity provider using SAML. This setup streamlines authentication by allowing users to log in with their existing company credentials, while giving admins centralized control over who can access Attio.
Enable Single Sign-On (SSO)
SSO can be set up in Attio by a workspace admin following these steps:
From the Security panel in Workspace settings, verify each of the domains that you wish for SAML to apply to. For example, if you wish for attio.com to be covered by your SAML installation or access management provider (such as Okta), you must verify attio.com using our DNS challenge method.
Once verified, click Enable SAML which will present the SAML configuration options.
Upload your IDP certificate and set the IDP Sign In URL.
Lastly, retrieve your unique SAML SP url for IDP-initiated flows from inside of the settings panel.
You'll need to ensure that the NameID is the email address of the user, as this is how Attio matches the account to the SAML token.