SSO
Single sign-on (SSO) lets people in your organization sign in to Venue.sh with your existing identity provider instead of a separate Venue.sh password. Admins configure SSO from settings, without needing the Venue.sh team to set it up for them.
Venue.sh supports SAML identity providers such as Okta and Keycloak. Each organization can have one SSO provider, mapped to a single email domain.
How Sign-In Works with SSO
When SSO is configured, Venue.sh routes users to your identity provider based on their email domain. Someone signing in with an address on your configured domain is sent to your identity provider to authenticate, then returned to Venue.sh.
Because accounts come from your identity provider, the Invited Users tab and the Invite user action are hidden for organizations with an SSO domain. Provision and deprovision people in your identity provider instead.
Adding a SAML Provider
- Admin access to your Venue.sh organization (Admin role)
- Admin access to your SAML identity provider
- The email domain your organization uses to sign in
Configuring Your Identity Provider
After creating the provider, Venue.sh generates the values your identity provider needs.
Managing a Provider
From the SSO page, you can do the following:
- View Setup Values - Reopen the ACS URL, SP metadata URL, and metadata XML at any time.
- Edit Configuration - Update the domain, issuer, entry point, or certificate. The Provider ID cannot be changed.
- Delete Provider - Remove the SSO configuration. Users then sign in with their Venue.sh credentials again.
Troubleshooting
| Situation | What to do |
|---|---|
| The SSO page is missing from Settings | The feature may not be enabled for your organization, or your role may not include organization update permission. Contact your Venue administrator. |
| Add SAML Provider is unavailable | Each organization can have only one SSO provider. Edit or delete the existing provider first. |
| Users are not routed to the identity provider | Confirm the Email Domain matches the domain on their email addresses. |
| Sign-in fails at the identity provider | Re-check the ACS URL and SP Entity ID in your identity provider against View Setup Values. |
| The certificate is rejected | Paste only the certificate body, without the BEGIN and END CERTIFICATE lines. |
| You cannot invite new users | Invitations are disabled for organizations with an SSO domain. Provision users in your identity provider instead. |
See Also
- Settings - Account and organization configuration.
- Users and Teams - Manage who can access your organization.
- RBAC - Roles and permissions across Venue.sh.