SSO / SAML Authentication
Enable Single Sign-On with your identity provider.
SSO / SAML Authentication
Enterprise Plan Feature
Enable Single Sign-On so your team can log in with their corporate identity provider (IdP).
Supported Providers
- Okta
- Azure Active Directory (Entra ID)
- Google Workspace
- OneLogin
- Any SAML 2.0 compliant provider
Setup
- Go to Settings → Security → SSO
- Click "Configure SSO"
- Enter your IdP details:
- Entity ID — Your IdP's entity/issuer URL
- SSO URL — The single sign-on endpoint
- Certificate — Your IdP's X.509 certificate
- Copy LemWatch's ACS URL and Entity ID into your IdP
- Test the connection
- Enable SSO enforcement (optional — require all team members to use SSO)
How It Works
- Team members visit LemWatch and click "Sign in with SSO"
- They're redirected to your corporate login page
- After authentication, they're automatically logged in to LemWatch
- New users are auto-provisioned with the Viewer role (configurable)
SSO Enforcement
When enabled, all team members must use SSO — password login is disabled. The organisation owner always retains password access as a fallback.
SCIM Provisioning (Coming Soon)
Automatic user provisioning and de-provisioning via SCIM protocol.