Skip to main content

Enterprise SSO and SCIM

Let your team sign in through Okta, Entra, Google Workspace, and more.

Written by Traian

Single sign-on lets the people who run your board sign in to the easyboard dashboard through your company's identity provider (Okta, Microsoft Entra, Google Workspace, OneLogin, and more) instead of a separate password. Directory sync (SCIM) goes a step further: it provisions and deprovisions dashboard members automatically from your directory, so someone who leaves your company loses access without anyone remembering to remove them.

Two things to know up front:

  • This is for your dashboard team, the admins who manage the board. Job seekers and employers on your public board keep their normal sign-in and are not affected. See candidate accounts for the public side.

  • SSO / SAML is an Enterprise plan feature.

Before you start

  • Your board must be on the Enterprise plan.

  • You need admin access to your identity provider (the ability to create an app or configure provisioning in Okta, Entra, Google Workspace, or similar). Keep its admin console open in another tab; the setup portal will give you values to copy across.

  • Nothing about your identity provider is stored in easyboard: the connection lives with WorkOS, the identity platform that powers easyboard sign-in, and you configure it through their hosted portal.

Open the SSO settings

  1. In the sidebar, click Settings (at the bottom), then click the Single sign-on card.

  2. You land on the Single sign-on & SCIM page.

On plans below Enterprise, the page shows a locked card reading SSO / SAML, "Available on Enterprise. Upgrade to unlock it.", with an Upgrade plan button. Upgrading is handled through your platform billing; see Your easyboard subscription.

The Single sign-on and SCIM page showing the Enterprise upgrade gate

Set up single sign-on

On Enterprise, the page shows two cards. Setup does not happen in the easyboard dashboard itself: each card opens a secure hosted portal (run by WorkOS, our identity platform) that walks you through your specific identity provider step by step, including the values to copy into Okta, Entra, or whichever provider you use.

  1. In the Single sign-on (SAML / OIDC) card, which reads No SSO connection yet before setup, click Set up SSO.

  2. You are redirected to the hosted setup portal. Pick your identity provider and follow the guided steps; you will typically create an app in your provider and exchange a few URLs and certificates, all shown in the portal with provider-specific instructions.

  3. When you finish (or leave), the portal sends you back to this settings page.

Your connection now appears in the card with a status badge: Active when it is working, Pending while setup is incomplete. To change or finish a connection later, click Manage SSO on the same card, which reopens the portal.

Connect directory sync (SCIM)

SCIM is optional and independent of SSO: you can run SSO alone, SCIM alone, or both together.

  1. In the Directory sync (SCIM) card, which reads No directory connected yet before setup, click Connect directory.

  2. The same hosted portal opens with guided steps for your directory (for example Okta or Entra provisioning). You will generate a SCIM endpoint and token to paste into your directory's provisioning settings.

  3. Finish, and you are returned to the settings page, where the directory is listed with its Active or Pending badge.

Once active, adding a person to the synced group in your directory gives them dashboard access, and removing them (or offboarding them from your company) revokes it automatically.

SSO, SCIM, and your Team page

Manual team management keeps working alongside SSO: the Team page still lists members and roles, and you can still invite people by email. SCIM simply automates the add-and-remove part from your directory. Roles for synced members are managed on the Team page like any other member.

Troubleshooting

  • The setup button shows an error. If you see "SSO / SAML is available on the Enterprise plan", your board is not on Enterprise; upgrade first. If you see "Couldn't open the setup portal", try again in a minute.

  • A connection stays Pending. Setup was not completed on the identity-provider side. Click Manage SSO to reopen the portal and finish the remaining steps.

  • You manage several boards. SSO is configured per workspace. If your team runs more than one board, repeat the setup in each workspace where you want SSO.

Did this answer your question?