Guide

Setting up single sign-on

Connect your identity provider so members sign in through it instead of a Skuvelo password.

Single sign-on lets members sign in through your identity provider (Okta, Google Workspace, Azure AD / Entra, or any SAML provider) instead of a Skuvelo password. An owner sets it up from Settings → Team & Roles.

What your identity provider needs from Skuvelo. The single sign-on card on Settings → Team & Roles shows three values to give your provider when you create the Skuvelo application there: the Entity ID, the ACS URL, and a metadata URL. Each has a Copy button.

What Skuvelo needs from your identity provider. Either paste the provider's metadata URL, or paste its metadata XML directly, then save.

Verifying your domain. Add the domain your members sign in with (for example example.com). Skuvelo gives you a DNS TXT record name and value to add at your DNS provider. Once it's added, come back and select Verify. Only members whose email address is on a verified domain are affected by the settings below.

Default role for new members. Choose the role a member gets the first time they sign in through single sign-on. This can be any role except Owner — ownership is never granted automatically.

Requiring single sign-on. Turn on "Require SSO for verified-domain members" once you've verified sign-in works, and members on that domain must use single sign-on going forward. Owners are the exception and keep signing in with a password and two-factor — this is the break-glass path if your identity provider is ever unreachable.

Trusting your identity provider's multi-factor. If your provider already enforces multi-factor authentication, turn on "Trust the identity provider's multi-factor" so Skuvelo doesn't ask members to set up a second, separate factor on top of it.

Removing someone. Removing a member at your identity provider takes effect the next time they try to sign in — Skuvelo doesn't poll your provider continuously. To cut off access immediately, remove them from Settings → Team & Roles directly; that takes effect right away.

What single sign-on doesn't do. It doesn't yet support automatic user provisioning (SCIM) — each member's first sign-in through your provider is what creates their Skuvelo membership, at the default role you chose above.

Try the plan on your own stock.

Start a trial with your own sales and stock, or look around the live demo first.