Set up single sign-on
Let your team sign in through Okta, Microsoft Entra ID, Google Workspace or any SAML or OpenID Connect provider.
Updated
Single sign-on lets people with your company’s email addresses sign in to CommentGate through your own identity provider. It is included on every plan. Owners and admins set it up, per brand, on Settings, then Security.
Before you start
- Admin access to your identity provider (Okta, Microsoft Entra ID, Google Workspace, or any provider that speaks SAML or OpenID Connect).
- Access to your domain’s DNS settings, to prove you own the email domain.
Set it up
- Under Everyone in this brand, find Single sign-on and select Set up.
- Under How your company signs in, choose OpenID Connect or SAML.
- In Email domain, type your company’s domain, like wildermere.com. People with addresses there will sign in this way.
- Create an app in your identity provider and copy its details into the form. For OpenID Connect: Issuer address, Client ID and Client secret. For SAML: Entity ID, Sign-in address and Signing certificate (including the BEGIN and END lines).
- Select Save. CommentGate now shows what your identity provider needs back: a Redirect address for OpenID Connect, or a Reply address (ACS URL) and Audience (entity ID) for SAML. Copy them into the app you created. For SAML, send the email address as an attribute named email.
Prove you own the domain
Your provider’s row shows Waiting for DNS and a TXT record to add.
- At your DNS provider, add a TXT record with the Record name and Record value (TXT) shown.
- Back in CommentGate, select Check DNS record.
DNS changes can take a while to spread. If the check fails, wait and try again. When it passes, the row says On.
Replace the client secret or certificate
Your provider’s row shows Client secret (OpenID Connect) or Signing certificate (SAML) as Saved. Nobody can read it back, including you. When your identity provider gives you a new one:
- Select Replace.
- Paste the new client secret or signing certificate.
- Select Save.
For SAML, a certificate cannot be swapped once people have signed in with the old one. Remove the setup and add it again with the new certificate.
How your team signs in
On the sign-in page, people choose Sign in with single sign-on, type their work email, and are taken to your company’s sign-in page.
- Someone signing in this way for the first time joins the brand as a Moderator. Change their role on Members if they need more. See Roles and what each one can do.
- Single sign-on is an extra way in. Email links and passkeys keep working.
Things to know
- Removing someone from your identity provider stops them signing in through it, but does not remove them from CommentGate. Remove them on Settings, then Members, too.
- There is no automatic user provisioning (SCIM). People join on first sign-in or by invitation.
- To add another email domain, select Add another domain. To stop using single sign-on for a domain, remove it from the same list. People can still sign in by email or passkey.
Every change is recorded in the audit log.
Related
- Two-step sign-in and passkeys Add a passkey or an authenticator app to your sign-in, and require two-step sign-in for everyone on your team.
- Invite your team Send someone a link to join your brand, choose their role, and add them to your other brands in one go.
- Roles and what each one can do Owner, admin, manager, moderator and client: what each role can see and change in a brand.
- The audit log See who signed in and who changed what in a brand, filter by person, area or date, and download it as a CSV.
Still stuck?
Tell us what you were trying to do and what happened. A person replies, usually within one business day.