Setting Up Single Sign-On

Modified on Tue, 1 Sep at 6:49 AM

Set up single sign-on (SSO) so your team signs into Lavalier with your company's identity provider. Lavalier uses the SAML 2.0 standard, and SSO can only be set up by an account Owner. The same page also lets you provision users automatically with SCIM.

Before You Start

  • Owner permissions in Lavalier (anyone else sees an "owner only" message).
  • SSO enabled for your account. SSO is part of your plan—if you're an owner and don't see it in Settings, contact your Lavalier account team.
  • A SAML 2.0-compatible identity provider (IdP) such as Okta or Microsoft Entra.
  • Access to add a DNS TXT record for your email domain.

Step 1: Open SSO Settings

Log in to Lavalier, click your name in the top-right, choose Settings, then open SSO & Provisioning.

Step 2: Give Your IdP Lavalier's Details

  1. Click Set up single sign-on to open the Set up SAML dialog. (If SSO was already started for your account, click Edit SAML config instead.)

  2. Under Service provider details, copy the Entity ID and ACS URL, and use Download metadata XML and Download .pem for the files your IdP may ask for.

  3. Copy the Sign-in URL too—set it as the app's sign-on URL in your IdP so members can launch Lavalier from their dashboard.

  4. Create and configure the SSO application in your identity provider using those values.

Everything your IdP needs is on this one screen, so you can finish the IdP side in a single pass.

Step 3: Add Your IdP's Metadata

Once its app is configured, your IdP generates metadata of its own. Back in Lavalier—click Edit SAML config if you closed the dialog—go to Your identity provider's details and either:

  • Click Upload metadata XML and select the file from your IdP. Lavalier fills in the fields for you.
  • Or use or enter manually: Your IdP's Entity ID, Your IdP's Sign-On URL, and the IdP signing certificate (PEM).

Click Save. The rest of the SSO settings appear once your configuration is saved.

Step 4: Verify Your Email Domain

You need a verified domain before you can turn SSO on—it's how teammates get routed to SSO by their email address.

  1. Under Verified domains, add your domain (e.g., acme.com). A Verify [domain] dialog opens automatically.

  2. Copy the Name / host and Value, then create a DNS TXT record with them at your DNS provider.

  3. Click Verify once the record has propagated. If you closed the dialog, click Set up DNS on the domain row to reopen it.

Step 5: (Optional) Adjust Advanced Options

In the same dialog, expand Advanced SAML options to map non-standard attributes, turn on Sign AuthnRequests (recommended), or turn on Require encrypted assertions. Most setups can leave these at their defaults.

Step 6: Test the Connection

Click Test SSO sign-in at the bottom of the dialog. Lavalier opens a test sign-in in a new tab and reports the result back to you.

Step 7: Turn SSO On

  1. Flip the Use single sign-on switch. (It stays disabled until you have a verified domain.)

  2. If an Enable SSO? warning appears, some people on your verified domains already have Lavalier accounts in another organization. Add them to your identity provider first, or they'll be locked out—then confirm.

  3. Lavalier shows your recovery codes once. Save them immediately (Step 8).

Once SSO is on:

  • Everyone with an email on a verified domain must use SSO—including owners. There's no owner-bypass toggle.
  • Users on unverified domains aren't affected and keep signing in as they do today.
  • You can't remove your last verified domain while SSO is on.

Step 8: Save Your Recovery Codes

Recovery codes let an owner sign in if your identity provider is ever unavailable. Turning SSO on generates a set for you if you don't have one and reveals it in a Your recovery codes dialog.

Save the codes now—ideally in a password manager—then click I've saved my codes.

Important: The codes are shown only once and can't be retrieved later. They're personal to you: anyone holding one can sign in as you, so don't share them.


Provision Users Automatically (SCIM)

The SSO & Provisioning page also supports SCIM, which lets your identity provider create, update, and deactivate Lavalier users automatically.

  • The SCIM section appears once you've set up SAML.
  • The Enable SCIM toggle unlocks once SSO is on.

See Setting Up SCIM Provisioning for the full setup.

What Your Team Sees

Once SSO is enabled, teammates enter their work email on the login page and are routed to your identity provider to sign in. You can also share the direct /sso/<slug> link as a bookmark or an app tile in your IdP.

What's next?

FAQ

Do I need anything from my identity provider before I start?

No. Lavalier's Entity ID, ACS URL, Sign-in URL, certificate, and metadata XML are all available the moment you click Set up single sign-on—before you've entered anything about your IdP. You only come back to Lavalier once your IdP has generated its own metadata.

Which format should I give my identity provider?

Most IdPs (Okta, Entra, Google, OneLogin) accept Lavalier's Download metadata XML file directly, which is the quickest path. If your IdP console asks for the raw certificate PEM or the XML pasted inline, expand Manual / advanced under Service provider details.

Your IdP may also ask for a request-signing or assertion-encryption certificate—use Download .pem for that.

Can I enter my IdP's details by hand instead of uploading metadata?

Yes. Under or enter manually, fill in Your IdP's Entity ID, Your IdP's Sign-On URL, and the IdP signing certificate (PEM). You can also drag and drop a .pem, .cer, or .crt file onto the certificate field, and the fields stay editable after an upload if you need to adjust anything.

How long does domain verification take?

DNS changes can take a while to propagate—up to your TXT record's TTL. If verification fails right after you publish the record, wait a few minutes and try again. If your DNS is managed by a team you can't reach quickly, your Lavalier account team can help you complete verification.

What happens the first time someone signs in through SSO?

Lavalier creates their account automatically (just-in-time provisioning) with the Team Member role—no invitation email needed.

Can I manage recovery codes later?

Yes. Use the Manage recovery codes link on the SSO & Provisioning page to Generate codes, Regenerate codes (which revokes the old set immediately), or Revoke all.

Each owner has their own set, and each code works once.


Troubleshooting

I don't see SSO & Provisioning in Settings

Solution: SSO is configured by account owners and must be enabled for your account. If you're an owner and still don't see it, contact your Lavalier account team to enable it.

I don't see Verified domains on the page

Solution: The rest of the SSO settings appear only after your IdP's metadata is saved. Finish Step 3, click Save, and the Verified domains section appears.

I can't turn SSO on

Solution: You need at least one verified domain before you can enable SSO—the switch is disabled until then, with "Verify a domain below to enable SSO" as its tooltip. Under Verified domains, add your domain and complete the DNS TXT verification, then try again.

A teammate sees "We couldn't complete SSO for this email"

Solution: The full message is "This can happen when your email is linked to multiple Lavalier accounts." It appears when someone's email is tied to more than one Lavalier account. They should contact their account owner or support@lavalier.ai for help signing in.

A teammate sees "Single sign-on isn't configured for that URL"

Solution: The /sso/<slug> address is wrong, or SSO isn't set up yet. Double-check the link matches the one in your SSO & Provisioning settings.

My identity provider is down and I can't sign in

Solution: Use a recovery code. Open the recovery sign-in page, enter your email and one of your recovery codes, and open the emailed sign-in link within 15 minutes. If you don't have codes, another owner with codes can sign in and help.

SSO stopped working after being fine

Solution: Your IdP's certificate may have expired. The SSO settings show an IdP signing certificate status that warns you as it nears expiry. Rotate the certificate in your identity provider, then click Edit SAML config in Lavalier and upload the updated metadata.

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article