Reducto supports Enterprise SSO, letting your team log in with your identity provider (IdP) credentials. This page covers how setup works and answers common questions from IT and security teams.
How SSO works at Reducto
Users sign in at accounts.reducto.ai. Enterprise SSO is configured per organization through a guided setup page. Once SSO is enabled for your organization, members can no longer log in with other methods such as email/password or magic link.
To get started, contact your Reducto account team or support. We will send you a shareable setup link that should guide you through the setup process.
Setup process
Request SSO for your organization
Contact your Reducto account team to enable Enterprise SSO for your organization. We can also generate a setup link for the person configuring your IdP, even if they do not have a Reducto account.
Follow the guided setup for your IdP
The setup page provides step-by-step guides for Entra ID (Azure AD), Okta, Google, OneLogin, JumpCloud, Duo, Rippling, and Ping Identity, plus a generic guide for any other SAML 2.0 or OIDC provider. It supplies the values to enter into your IdP, including the ACS URL and SP Entity ID.
Provide your IdP details
For SAML, you enter your IdP SSO URL, IdP Entity ID, and the token signing certificate. The guide then walks through mapping user attributes and, optionally, roles. See Mapping roles from your IdP below. Finish and go live
After clicking Finish & Go Live, the setup page shows your organization’s login URL in the form https://auth.reducto.ai/saml/{org_slug}/login.
Mapping roles from your IdP
Reducto gives every user it creates through SSO the Member role. To assign Admin or Owner automatically, send the role from your IdP in the SAML response. Reducto reads it in one of two ways:
- A
role attribute whose value is exactly Owner, Admin, or Member.
- Group membership: a group named
role_{Role} or role_{label}_{Role}, sent in a groups attribute. role_Owner, role_Admin, and role_Member are the simplest form. A user in role_Owner gets the Owner role.
To tell the group apart from other applications’ groups in your IdP, insert one label between the prefix and the role, for example role_Reducto_Owner. The label cannot contain underscores. role_Reducto_Production_Owner does not match.
Values must match the Reducto role names exactly. If the SAML response does not include a recognized role, the user gets the Member role.
Role mapping is available for SAML connections only. OIDC connections provision every user as a Member; change roles afterwards from the organization settings page.
The guided setup page repeats these instructions for your IdP. The provider-specific steps are summarized below.
Entra ID (Azure AD)
Okta
Google Workspace
Other IdPs
Send the role as a claim
- In your Reducto enterprise application, open Single sign-on and edit Attributes & Claims.
- Add a new claim with Name
role, Namespace http://schemas.xmlsoap.org/ws/2005/05/identity/claims, Source Attribute, and Source attribute user.assignedroles.
Define the app roles
- Go to App registrations, select the Reducto app, and open App roles.
- Click Create app role once for each of
Owner, Admin, and Member. Set both Display name and Value to the role name.
- Set Allowed member types to Users/Groups, add a description, leave the role enabled, and save.
When you assign a user or group to the enterprise application, pick the app role to grant. Assigning a group gives every member of that group the selected Reducto role.
- Go to Directory > Profile Editor and open the profile for the Reducto SAML app.
- Click Add Attribute. Set Display name and Variable name to
role. Set Attribute type to Group so the value can be set per group. Alternatively, choose Personal and enable Enum with Owner, Admin, and Member as both display name and value.
- In the Reducto SAML app, open General > SAML Settings > Attribute Statements and add an attribute with Name
role and Value appuser.role.
- When assigning a group (or user) to the app, set
role to Owner, Admin, or Member.
Google sends group membership rather than a role attribute.
- In Google Admin, create groups named
role_Owner, role_Admin, and role_Member (or with a suffix such as role_Reducto_Admin) and add users to them.
- In the Reducto SAML app, open Attribute mapping and under Group membership (optional) select those groups and set App attribute to
groups.
Any SAML 2.0 IdP works with either method:
- Add an attribute statement named
role whose value is Owner, Admin, or Member, populated from a user or group property in your directory.
- Or create groups named
role_Owner, role_Admin, and role_Member and include the user’s groups in the SAML response as a groups attribute.
The guided setup page lists the exact steps for OneLogin, JumpCloud, Duo, Rippling, and Ping Identity.
Frequently asked questions
SAML support
Yes. Reducto supports SAML 2.0, with both SP-initiated and IdP-initiated logins. OIDC is also supported.
Which identity providers are supported?
Guided setup is available for Entra ID (Azure AD), Okta, Google, OneLogin, JumpCloud, Duo, Rippling, and Ping Identity. Any other IdP that supports SAML 2.0 works through the generic SAML integration.
What are the ACS URL and Entity ID?
Both values are shown in the guided setup page for your organization. Enter them into your IdP when creating the application (in Entra ID, these are the Reply URL and Identifier fields in Basic SAML Configuration).
Is the Sign on URL required? (Entra ID)
No. In Entra ID’s Basic SAML Configuration, only the Identifier (Entity ID) and Reply URL (ACS URL) are required. The Sign on URL is only used when starting login from a bookmark or the My Apps portal tile. You may leave it blank, or set it to your organization’s login URL: https://auth.reducto.ai/saml/{org_slug}/login.
Can you provide a Service Provider metadata file?
Yes. After completing the setup guide and clicking Finish & Go Live, take your organization’s login URL (https://auth.reducto.ai/saml/{org_slug}/login) and replace /login with /metadata. Navigating to that URL downloads the SP metadata XML, which can be used for a Relying Party Trust configuration.
Do you support automatic token signing certificate rollover?
No. The IdP signing certificate is provided during setup. When your IdP rotates its token signing certificate, update the SAML connection with the new certificate by revisiting the setup page. We recommend configuring certificate expiry notifications in your IdP.
Attributes and provisioning
Which attributes should the SAML response include?
The SAML response should include: Do you support mapping roles from our IdP?
Yes, for SAML connections. Send a role attribute with the value Owner, Admin, or Member, or put users in groups named role_Owner, role_Admin, or role_Member and include group membership in the SAML response. Users without a recognized role become Members. See Mapping roles from your IdP for per-IdP steps. Can we map roles over OIDC?
Not yet. OIDC connections provision every user as a Member. An Owner or Admin can change roles afterwards from the organization settings page. If role mapping matters for your rollout, configure SAML instead of OIDC.
Do you support Just-In-Time (JIT) provisioning?
Yes. Users are provisioned automatically on their first SSO login.
Do you support SCIM provisioning?
SCIM is available for Okta, Entra ID, OneLogin, JumpCloud, and Ping Identity. Contact your Reducto account team to confirm availability for your organization.
Login behavior
Can members still log in with a password after SSO is enabled?
No. Once Enterprise SSO is enabled for your organization, members (and users sharing your organization’s email domain) can only log in through your IdP.
Do you support IdP-initiated login?
Yes. Both SP-initiated and IdP-initiated logins are supported.
Who can configure SSO for our organization?
Users with a role that includes the Enterprise SSO permission can configure it from the organization settings page.
Need help?
Contact support@reducto.ai or your Reducto account team for SSO setup assistance.