Enterprise single sign-on (SAML)
Sign in through your own identity provider — Entra ID, Okta, or any SAML 2.0 IdP. Your MFA and offboarding policies apply to Cybermatic automatically.
- 1Before you begin. Enterprise single sign-on lets your team sign in to Cybermatic through your own identity provider — Microsoft Entra ID, Okta, or any SAML 2.0 provider — instead of a Cybermatic password. Your MFA policies, conditional access, and offboarding apply automatically: disable a user in your directory and their Cybermatic access ends with it. SSO is available on Enterprise plans (early access). Setup is a short exchange between your IT team and ours: you create a SAML app in your identity provider using the values below, send us its metadata URL, and we activate your domain — typically same-day. Setup is self-serve: a workspace administrator opens Settings → Single sign-on in the Cybermatic portal, which shows your two values (ACS URL and Entity ID) with copy buttons. Your IT admin creates the SAML app with those values, then the administrator pastes the app's metadata URL back into the same page. You need: admin access to your identity provider, and these two Cybermatic values (also shown with copy buttons in Settings → Single sign-on): ACS URL (Reply URL / Single sign-on URL): https://us-east-1s9yrzjdgm.auth.us-east-1.amazoncognito.com/saml2/idpresponse Entity ID (Identifier / Audience URI): urn:amazon:cognito:sp:us-east-1_s9YrzJDGm
- 2Option A — Microsoft Entra ID. 1. In the Entra admin center, go to Enterprise applications → New application → Create your own application. 2. Name it Cybermatic, choose "Integrate any other application you don't find in the gallery (Non-gallery)", and Create. 3. Open the app → Single sign-on → SAML. 4. In Basic SAML Configuration: Identifier (Entity ID): the Entity ID value above. Reply URL (Assertion Consumer Service URL): the ACS URL we sent you. 5. In Attributes & Claims, confirm the default emailaddress claim is present (Entra includes it by default as http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress — that exact claim is the one Cybermatic reads). 6. Under Users and groups, assign the users or groups who should have Cybermatic access. 7. In the SAML Certificates section, copy the App Federation Metadata URL. 8. Give that metadata URL to your Cybermatic workspace administrator — they paste it into Settings → Single sign-on to activate.
- 3Option B — Okta. 1. In Okta Admin, go to Applications → Create App Integration → SAML 2.0. 2. Name it Cybermatic. 3. In SAML Settings: Single sign-on URL: the ACS URL we sent you. Audience URI (SP Entity ID): the Entity ID value above. 4. Add an attribute statement — Name: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress (paste the full URI as the attribute name), Name format: URI Reference, Value: user.email. 5. Finish, then assign the app to the people or groups who should have access. 6. On the app's Sign On tab, copy the Metadata URL. 7. Give that metadata URL to your Cybermatic workspace administrator — they paste it into Settings → Single sign-on to activate.
- 4Step 2 — Activate in the portal. A Cybermatic workspace administrator opens Settings → Single sign-on, enters your email domain and the metadata URL, and selects Activate. If the domain matches your workspace owner's email domain, SSO is live immediately; other domains (e.g. subsidiaries) are verified by our team first, typically the same business day. From then on: your team uses "Sign in with SSO (enterprise)" on the Cybermatic login page, enters their work email, and is sent to your identity provider to authenticate. On first sign-in, each user automatically joins your Cybermatic workspace with the default role we agreed (viewer unless you asked otherwise); your workspace administrators can promote individuals under Settings → Team.
- 5What changes for your team. • No Cybermatic passwords exist for SSO users — nothing to phish, rotate, or forget. • Your MFA, device, and conditional-access policies apply to Cybermatic automatically. • Offboarding is instant: disable the user (or unassign the app) in your directory and their access ends. • Your workspace owner's original email/password sign-in keeps working as a break-glass account — we recommend keeping it secured with a strong password and MFA rather than removing it.
- 6Troubleshooting. "Single sign-on isn't set up for that domain" — we haven't activated your domain yet, or the user typed a personal email; SSO matches on your company email domain. Sign-in loops or an identity-provider error — the ACS URL or Entity ID in your SAML app doesn't exactly match the values we sent; re-check both, character for character. A user lands in Cybermatic but sees an empty workspace — their email domain differs from the registered one (e.g. a subsidiary domain); tell us each additional domain and we'll register it to the same workspace. A user should be an administrator — any existing workspace admin can promote them under Settings → Team after their first SSO sign-in.
Tip: The whole exchange is two values from us, one metadata URL from you. Most IT teams complete their side in under fifteen minutes — the same app-creation flow they've done for every other SaaS tool.