Skip to main content
Enterprise PortalSetting Up Single Sign-On (SAML)

Setting Up Single Sign-On (SAML)

Single Sign-On is available on the Scale tier and uses SAML 2.0. Once it is active, your team signs in with the same corporate credentials they use for everything else, and you manage who has access from your identity provider.

One email input, no button to pick

The portal sign-in screen only ever shows one field: email. When someone enters their address, VidScore looks up the domain. If that domain has SSO configured, we redirect straight to your IdP. If not, we fall back to sending a one-time code. Your team never has to choose between an "SSO login" button and an "email login" button, the router decides based on the email they typed.

Requesting SSO

An admin on your account opens Settings, Security, Request SSO, and submits the email domain (for example, acme.com) along with which provider you use. The dropdown offers Okta, Microsoft Entra ID, Google Workspace, OneLogin, JumpCloud, and Other. VidScore receives the request and reaches out to the IT contact you listed to collect SAML metadata (the IdP metadata URL or XML file, entity ID, and ACS URL). We register the provider, activate it, and let you know it is live. Typical turnaround is one to two business days.

SSO proves identity, membership still controls access

A successful SAML assertion confirms a user is who they say they are. It does not grant portal access on its own. Your team list in the portal is still the gate. An admin has to invite each user by email before that user can sign in, whether or not their domain has SSO. This is deliberate: SSO is not a back door that lets anyone with a @acme.com mailbox into your delivery feed.

What a team member sees

Enter your work email on the portal sign-in page, get redirected to your IdP (Okta, Azure, Google, etc.), authenticate there with your usual credentials and any MFA your company enforces, then get redirected back to the VidScore portal already signed in. There is no one-time code to copy, no second step.

Downgrades and fallback

If you leave the Scale tier for any reason, SSO providers auto-disable on your next billing cycle and the portal silently falls back to OTP. Your team keeps access, they just go back to receiving a 6-digit code in their inbox. Re-upgrading to Scale reactivates the same provider, you do not have to re-register.

Detailed reference

What you can expect

  • SAML 2.0
  • Okta, Microsoft Entra ID, Google Workspace, OneLogin, JumpCloud, and generic SAML
  • Email-as-router sign-in with one input field
  • Audit log events: settings.sso_configured, settings.sso_disabled, auth.sso_login

Limits

  • SCIM user provisioning is not yet available, admins still invite users manually
  • OIDC providers are not supported in v1, SAML only
  • SSO does not replace the team list, membership is still required
  • SSO is not available on Starter or Growth tiers

If something looks off

If a team member reports they are stuck in a redirect loop or see an "unauthorized" error after authenticating with their IdP, the most common cause is that they have not been invited to the portal yet. Check the team list first. If they are listed and still cannot sign in, contact [email protected] with the email address and approximate sign-in time so we can trace the SAML assertion.

Important context

The email-as-router design means you do not need to train your team on a new login flow. They enter their email like always, and we pick the right path. This also means a user can have SSO enforced even if they try to click an old OTP link, the router always wins.

Last updated 2026-04-14

Did this help?

Related articles

Still need help?

We're here if you need us.