Skip to main content

Configure single sign-on

Single sign-on (SSO) lets members of a Catalyst organization sign in with their company account, through a SAML 2.0 identity provider (IdP) such as Okta, Microsoft Entra ID or Google Workspace. When someone signs in with an email address using the specified domain, Catalyst sends them to the configured IdP for authentication. Users with an email address using any other domain keep signing in as before.

important

SSO changes how people authenticate, not what they can access. Each person still needs an invitation to the organization, and their role still decides what they can do. Catalyst rejects an SSO sign-in from anyone who has not been explicitly invited.

Prerequisites​

  • SSO enabled for your organization. SSO is not part of the self-serve plans. Contact Diagrid Support with your company's email domain, for example example.com. Diagrid enables SSO for your organization and allows that domain. Until then, the Single sign-on page in the console explains that SSO is not enabled.
  • A global Admin role (cra.diagrid:admin). Admins scoped to a project cannot manage SSO. See the permission matrix.
  • Admin access to your IdP, to create a SAML application for Catalyst.

Each email domain can belong to only one SSO connection across Diagrid. If your company already signs in to another Diagrid organization through SSO on the same domain, for example in the Dapr Ops Dashboard, ask Diagrid Support to share that connection with this organization instead of creating a new one.

Create the connection​

The connection is bidirectional. The IdP needs two values from Catalyst, and Catalyst needs two values from the IdP. The console shows the Catalyst values before you save any changes, so create the IdP application first.

  1. In the Catalyst console, open Identity and Access › Single sign-on and select Add connection.
  2. Enter a Name for the connection and your company's Email domain, without the @. The connection type is always SAML 2.0.
  3. In your IdP, create a SAML application for Catalyst. Copy the Callback URL and Entity ID from the console into it.
  4. Configure the IdP application to send each user's email address when they sign in. In Okta, add an attribute statement for user.email, or sign-in fails.
  5. Copy the IdP application's sign-in endpoint into the console, and upload its signing certificate.
  6. Optionally, add the IdP's sign-out endpoint so that signing out of Catalyst also signs users out of your IdP.
  7. Select Create.

Your IdP may use different names for these values:

Catalyst consoleOktaMicrosoft Entra IDGoogle Workspace
Callback URLSingle sign-on URLReply URL (Assertion Consumer Service URL)ACS URL
Entity IDAudience URI (SP Entity ID)Identifier (Entity ID)Entity ID
Sign-in endpointIdentity Provider Single Sign-On URLLogin URLSSO URL
Sign-out endpointIdentity Provider Single Logout URLLogout URLNot supported
Signing certificateX.509 CertificateCertificate (Base64)Certificate

The signing certificate must be a PEM file: a text file that starts with -----BEGIN CERTIFICATE-----. A binary .cer file is not accepted.

If saving fails because the email domain is not enabled, either Diagrid has not enabled that domain for your organization yet, or another SSO connection already uses it. Contact Diagrid Support in both cases.

Invite your users​

Invite each person who should sign in through SSO, with the same email address their IdP account uses. See Invite new users.

Invite people before they first try to sign in. A sign-in through your IdP from an email address that has not been invited is rejected.

Test the connection​

  1. Open a private browser window and go to the Catalyst console.
  2. Enter the email address of an invited user. Catalyst sends you to your IdP instead of asking for a password.
  3. Sign in at your IdP.

The first time each user signs in through SSO, they are asked to sign in twice. This is expected as the first sign-in links their IdP account to their Catalyst invitation.

When you test several users on one machine, your IdP can silently sign you in as the previous user, because the email address you type in Catalyst only chooses where to send you. Sign out of your IdP, or use a new private window, between users.

Manage the connection​

An organization can only have one SSO connection. The SSO page shows its settings, and the callback URL and entity ID to enter in your IdP again if you need them. These two values never change for a connection. If you delete a connection and create a new one, update your IdP application with the new values.

  • Edit the connection to update its name or endpoints, or to replace the signing certificate. When your IdP rotates its signing certificate, upload the new one in Catalyst at the same time. Sign-ins fail while the two disagree.
  • Delete the connection to stop SSO for your domain. Members on that domain can no longer sign in through your IdP. If the connection is shared with another Diagrid organization, deleting it here only removes it from this organization.

Remove access for people who leave​

Disabling someone in your IdP stops them signing in through SSO. It does not remove them from your Catalyst organization, and it does not revoke the API keys they created. Remove them from the organization in Catalyst as well, and delete or rotate any keys your automation depends on. Use service accounts for automation, so it does not depend on one person's account.