KuikCodeDocs
Account & billing

Single Sign-On

Let your team sign in to KuikCode through Okta, Microsoft Entra ID, Google Workspace or any SAML 2.0 identity provider, and require it for everyone at your domain.

Enterprise

SSO is part of the Enterprise plan and is turned on per workspace. Choose Get a quote on the plans page in the dashboard and tick SSO, or email business@kuikcode.com.

How it works

  • People with an address at your company's domain choose Continue with SSO on the sign-in page, type their work email, and sign in through your identity provider.
  • Their first sign-in creates their KuikCode account and adds them to your workspace as a Member. Admins can promote them in Settings, Members.
  • A new person needs a free seat in the workspace. When there is none, the sign-in stops and says to ask an admin.
  • Sessions that come from Single Sign-On end after 24 hours. Someone your identity provider no longer lets in is out within a day.
  • If your identity provider is already signed in as someone else, on a shared computer for example, KuikCode stops and names that account instead of signing it in. Sign out of your identity provider, then try again.

Set it up

Owners and admins do this in Settings, Single Sign-On.

1. Create the app in your identity provider

The tab shows two values, named the way your provider's form names them:

OktaMicrosoft Entra IDGoogle Workspace
Where people returnSingle sign-on URLReply URL (Assertion Consumer Service URL)ACS URL
KuikCode's identityAudience URI (SP Entity ID)Identifier (Entity ID)Entity ID

Okta. Go to Applications, Create App Integration, SAML 2.0. Paste the two values. Set Name ID format to EmailAddress and Application username to Email, then assign the people or groups who should get in. For real names in KuikCode, add the Attribute Statements email, firstName and lastName; newer Okta versions add these on the app's Sign On tab after it's created. Without them, a new person's name starts as their email address.

Microsoft Entra ID. Go to Enterprise applications, New application, Create your own application, then Single sign-on, SAML. Paste the two values under Basic SAML Configuration and set Unique User Identifier to user.mail. The default claims work as they are. Then assign users and groups.

Google Workspace. In the Admin console, go to Apps, Web and mobile apps, Add app, Add custom SAML app. Paste the two values, set Name ID format to EMAIL and Name ID to Basic Information, Primary email. Map Primary email to email, First name to firstName and Last name to lastName. Then turn the app on for the right organizational units.

Other SAML 2.0 providers. Create a SAML application with the two values, send the person's email address as the Name ID, and add email, firstName and lastName attributes if your provider lets you.

2. Connect it

Paste your provider's metadata URL, upload its metadata XML, or enter its sign-in URL, entity ID and signing certificate by hand. Then enter your company's email domain; it covers its subdomains too. Public email services such as gmail.com can't be used, and one domain belongs to one workspace.

3. Verify your domain

Add the TXT record the tab shows at your DNS provider, then choose Verify domain. DNS changes can take a few minutes, sometimes an hour.

4. Test a sign-in

Choose Test sign-in. A new tab opens where you sign in through your identity provider as yourself, and your KuikCode session switches to Single Sign-On. Your KuikCode email has to be at the domain: until Single Sign-On is on, only the workspace's owners and admins get through.

5. Turn it on

Switch on Turn on Single Sign-On. People at your domain can now sign in this way, and new ones join the workspace as Members.

A tile in the app launcher

Sign-ins always start at KuikCode, which protects against replayed responses, so the tile your identity provider shows for the SAML app can't sign anyone in on its own: it opens the KuikCode sign-in page, which asks for a work email. Once Single Sign-On is on, the tab shows a link that skips that step: https://app.kuikcode.com/sign-in/sso?domain=yourcompany.com.

  • Okta: add a Bookmark app with that link, assign it to the same people, and hide the SAML app's own tile (its General tab, Do not display application icon to users).
  • Microsoft Entra ID: put the link in Sign on URL, under Basic SAML Configuration. The My Apps tile then starts at KuikCode.

Require Single Sign-On

Require Single Sign-On makes it the only way in for everyone at your domain. Passwords, Google and GitHub are refused, so are password resets, and anyone signed in another way is signed out. Owners keep their password, so a broken identity provider or an expired certificate can never lock your company out of its codes.

When someone leaves

KuikCode doesn't sync users from your identity provider yet, so:

  • Unassign them in your identity provider. They can't sign in again, and their last session ends within 24 hours.
  • Remove them in Settings, Members to end their access at once: a session they have open through Single Sign-On ends too. Someone you remove can't come back through Single Sign-On until you invite them again.

Renewing the certificate

Identity providers rotate their signing certificates. The tab shows when yours expires and warns 30 days ahead. Choose Update and connect the new metadata or certificate; sign-ins keep working, nobody has to sign in again.

Disconnecting

Disconnect removes the connection. Everyone stays in the workspace and signs in with a password or Google again; people who only ever used Single Sign-On set a password with Forgot password.

Every change to Single Sign-On emails the workspace's owners, with the name of whoever made it.

On this page