Articles in this section

Single Sign-On (SSO) in Spekit: Overview & Setup

Getting started with Single Sign-On in Spekit? This guide covers what SSO is, key terminology, supported Identity Providers, Just-in-Time provisioning, and how to complete your SSO/SCIM configuration.


1. Understanding Single Sign-On (SSO)

Single Sign-On (SSO) is an authentication process that allows users to access multiple applications or services using a single set of login credentials, such as a username and password. SSO simplifies the user experience by eliminating the need to remember multiple passwords and streamlines the login process.


2. SSO/SCIM Terminology

Before connecting your Spekit account with SSO, familiarize yourself with the following core terms:

  • IdP (Identity Provider): A service that stores and verifies digital user identities. Popular examples include Okta, Ping Identity, PingFederate, OneLogin, and Entra ID (Azure).
  • SAML (Security Assertion Markup Language): An XML-based standard for exchanging authentication and authorization data between parties, particularly between an Identity Provider (IdP) and a Service Provider such as Spekit.
  • JIT (Just-In-Time): A user provisioning method for on-demand account creation. When a user accesses Spekit for the first time through SSO, JIT automatically creates a user account for them.
  • SCIM (System for Cross-domain Identity Management): An alternative user provisioning method that automates user management tasks such as account creation, updates, and deactivation within Spekit.
  • IdP-Initiated Login: An SSO authentication flow where the login process is initiated from within your IdP rather than from the Spekit login page.
  • SP-Initiated Login: An SSO authentication flow where the login process is initiated from the Spekit login page rather than from within your IdP.

3. SSO Identity Provider (IdP) Compatibility

SSO Provider SAML 2.0 Supported SCIM Supported
Okta
Entra ID (Azure)
Google Workspace
JumpCloud
OneLogin
PingFederate
PingOne

Note: If your IdP is not listed above, Spekit cannot guarantee full functionality. Please contact your Customer Success Manager or support@spekit.co for more information.


4. Just-in-Time (JIT) Provisioning

What do I need to know about JIT provisioning in Spekit?

Spekit supports Just-in-Time (JIT) provisioning. Here are the key things to understand before getting started:

  • When SSO is configured using JIT, only the SAML portion is complete - SCIM is not required.
  • User accounts are created automatically on first login, but user management in Spekit is handled manually by Spekit Account Admins. For example, if someone leaves your company, their Spekit account must be manually disabled - JIT cannot automatically remove users.
  • Accounts are created upon a user's first login. For example, when a user is assigned the Spekit app in Okta and clicks the Spekit tile for the first time, their Spekit account is created automatically at that moment.
  • Teams (referred to as Groups in some IdPs) must be created and managed by users with the Spekit Account Admin role.
  • Accounts provisioned with JIT are added to the default All Spekit Users team with Viewer permissions. Spekit Account Admins manage access to any additional custom teams manually.
  • There are multiple ways for users to sign into the Spekit Chrome Extension - the SSO IdP administrator can decide how to direct users.
  • Users do not need to constantly re-authenticate to the Chrome Extension once they've logged in.
  • The IdP administrator must assign the Spekit tile in their IdP (e.g. Okta) to any users who need access to Spekit.

5. How to Enable and Complete SSO/SCIM Setup

Prerequisite: You must have Spekit Account Admin permissions and have SSO/SCIM enabled in your Spekit instance before proceeding. If the Connect with SSO/SCIM button isn't visible under Settings → Connect, contact your Customer Success Manager or support@spekit.co to have it enabled.

  1. Go to the Spekit Web App, click Settings, then Connect, and click the blue Connect with SSO/SCIM button.
Connect with SSO/SCIM button
  1. You'll be prompted to map your existing Spekit users to their IdP profiles, which prevents duplicate accounts from being created when users are provisioned through SSO. Click Download to get the Excel sheet containing your existing Spekit users.

Important: When working with the downloaded sheet: do not rename the file; do not modify columns A or B; only edit column C (the IdP email); do not remove any rows; and do not add or remove users in Spekit while the sheet is downloaded and being edited.

Connect existing user data modal
  1. Open the downloaded sheet, look for duplicate email addresses or a blank IdP Email field, and confirm the IdP Email column matches each user's profile exactly. Update any that are incorrect, then save the file.
  2. Click Choose File, select your updated sheet, and click Upload.
  3. On the Workspace Setup screen, enter a unique Workspace name for your organization - in most cases, this will be your company name.

Note: Users may need your Workspace name for SP-initiated logins, so choose a name your team can easily remember.

Workspace Setup screen

What's next? Spekit will guide you through step-by-step walkthroughs to set up SAML and SCIM for your selected IdP. Follow the walkthrough closely, as it includes unique URLs and organization-specific details required for the setup. Have more questions? Check out the Single Sign-On FAQs for more information.

 

Was this article helpful?
0 out of 0 found this helpful