Overview
Single Sign-On (SSO) allows your team members to authenticate using your organization’s identity provider (IdP). This provides centralized authentication management and enhanced security.SSO functionality is coming soon. This page describes the planned features.

Accessing SSO Settings
What is SSO?
Single Sign-On allows users to:| Benefit | Description |
|---|---|
| One Password | Use existing corporate credentials |
| Centralized Access | IT controls access from one place |
| Automatic Provisioning | Users created automatically on first login |
| Automatic Deprovisioning | Access revoked when removed from IdP |
| Enhanced Security | Leverage your IdP’s security features |
Supported Identity Providers
SSO will support SAML 2.0 compatible identity providers including:| Provider | Status |
|---|---|
| Okta | Planned |
| Azure AD | Planned |
| Google Workspace | Planned |
| OneLogin | Planned |
| Other SAML 2.0 | Planned |
Enabling SSO
These steps will be available when SSO launches.
SSO Configuration
Required Settings
| Setting | Description |
|---|---|
| Entity ID | Your IdP’s entity identifier |
| SSO URL | The URL where users are redirected for authentication |
| Certificate | Your IdP’s X.509 certificate for signature verification |
Optional Settings
| Setting | Description |
|---|---|
| SLO URL | Single Logout URL for sign-out propagation |
| Enforce SSO | Require all users to authenticate via SSO |
| Auto-provision | Automatically create users on first SSO login |
Domain Verification
Before enabling SSO, you’ll need to verify ownership of your email domain:SSO Enforcement
Soft Enforcement
Users can choose to sign in with SSO or email/password.Hard Enforcement
All users with your domain’s email must use SSO. Email/password login is disabled.User Experience
First-Time SSO Login
- User visits Royaltyport login page
- Enters email address
- Redirected to organization’s IdP
- Authenticates with corporate credentials
- Redirected back to Royaltyport
- Account created (if auto-provisioning enabled) or linked
Returning SSO Login
- User visits Royaltyport login page
- Enters email address
- Redirected to IdP (may be automatic if already logged in)
- Redirected back to Royaltyport, logged in
Permission Requirements
| Action | Required Role |
|---|---|
| View SSO settings | Admin, Owner |
| Configure SSO | Admin, Owner |
| Enable/disable SSO | Admin, Owner |
| Verify domain | Admin, Owner |
Security Considerations
Certificate rotation
Certificate rotation
Plan for certificate rotation before your IdP certificate expires.
Backup access
Backup access
Maintain at least one Owner account that can access without SSO in case of IdP issues.
Test before enforcing
Test before enforcing
Always test SSO with a few users before enforcing it organization-wide.
Monitor failed logins
Monitor failed logins
Use audit logs to monitor for failed SSO authentication attempts.
Troubleshooting
SSO login fails
SSO login fails
Check that your IdP configuration matches the settings in Royaltyport. Verify the certificate hasn’t expired.
User not provisioned
User not provisioned
Ensure auto-provisioning is enabled or manually invite the user before they attempt SSO login.
Domain verification fails
Domain verification fails
DNS changes can take up to 48 hours to propagate. Verify the TXT record is correctly added.
Locked out of organization
Locked out of organization
Contact Royaltyport support if all Owners are locked out due to SSO issues.