- Set up: after verifying your domain, you connect your IdP through a self-service wizard that exchanges SAML or OIDC details and maps user attributes. See Set up SSO.
- Maintain: SAML connections verify each login against your IdP’s signing certificate. When that certificate expires or your security team rotates it, you update ION with the new one, coordinated with the IdP switch. OIDC keys rotate automatically. See Rotate your SAML signing certificate.
- Retire: disabling SSO removes the connection and returns your team to email and password sign-in without deleting any accounts. See Disable SSO.
SSO
Overview
The life of an SSO connection in ION: set it up, keep its certificate current, and retire it.
An SSO connection hands authentication to your identity provider (Okta, Microsoft Entra ID, Google Workspace, ADFS, or another SAML or OIDC provider) and has a life beyond initial setup: