Skip to main content

Single sign-on (SSO): OIDC & SAML

Let your team sign in through Okta, Entra ID, Google Workspace, or any IdP.

Yardstick supports enterprise single sign-on over both OIDC and SAML, so it works with Okta, Microsoft Entra ID, Google Workspace, ADFS, and any standards-compliant identity provider. Once configured, anyone whose email matches your company domain signs in with the "Sign in with SSO" option on the login page; Yardstick routes them to your IdP automatically.

Setup is owner or admin only, under Settings, in the Enterprise SSO card. Pick a protocol:

  • OIDC: enter your issuer URL plus the client ID & secret from the app you

created in your IdP. Yardstick discovers the endpoints automatically (or you can enter them manually under Advanced). After adding, you get the redirect URL to paste into your IdP's app config.

  • SAML: paste your IdP's metadata XML (recommended), or enter the sign-on URL

and signing certificate manually. After adding, you get the ACS URL and SP metadata URL to paste into the IdP.

Secrets are write-only: once saved, Yardstick never displays your client secret or certificate again. SSO is part of the Enterprise plan and is enabled for every workspace during the beta.

Did this answer your question?