Skip to main content
Reducto supports Enterprise SSO, letting your team log in with your identity provider (IdP) credentials. This page covers how setup works and answers common questions from IT and security teams.

How SSO works at Reducto

Users sign in at accounts.reducto.ai. Enterprise SSO is configured per organization through a guided setup page. Once SSO is enabled for your organization, members can no longer log in with other methods such as email/password or magic link. To get started, contact your Reducto account team or support. We will send you a shareable setup link that should guide you through the setup process.

Setup process

1

Request SSO for your organization

Contact your Reducto account team to enable Enterprise SSO for your organization. We can also generate a setup link for the person configuring your IdP, even if they do not have a Reducto account.
2

Follow the guided setup for your IdP

The setup page provides step-by-step guides for Entra ID (Azure AD), Okta, Google, OneLogin, JumpCloud, Duo, Rippling, and Ping Identity, plus a generic guide for any other SAML 2.0 or OIDC provider. It supplies the values to enter into your IdP, including the ACS URL and SP Entity ID.
3

Provide your IdP details

For SAML, you enter your IdP SSO URL, IdP Entity ID, and the token signing certificate. The guide then walks through mapping user attributes and, optionally, roles. See Mapping roles from your IdP below.
4

Finish and go live

After clicking Finish & Go Live, the setup page shows your organization’s login URL in the form https://auth.reducto.ai/saml/{org_slug}/login.

Mapping roles from your IdP

Reducto gives every user it creates through SSO the Member role. To assign Admin or Owner automatically, send the role from your IdP in the SAML response. Reducto reads it in one of two ways:
  • A role attribute whose value is exactly Owner, Admin, or Member.
  • Group membership: a group named role_{Role} or role_{label}_{Role}, sent in a groups attribute. role_Owner, role_Admin, and role_Member are the simplest form. A user in role_Owner gets the Owner role.
To tell the group apart from other applications’ groups in your IdP, insert one label between the prefix and the role, for example role_Reducto_Owner. The label cannot contain underscores. role_Reducto_Production_Owner does not match. Values must match the Reducto role names exactly. If the SAML response does not include a recognized role, the user gets the Member role.
Role mapping is available for SAML connections only. OIDC connections provision every user as a Member; change roles afterwards from the organization settings page.
The guided setup page repeats these instructions for your IdP. The provider-specific steps are summarized below.
Send the role as a claim
  1. In your Reducto enterprise application, open Single sign-on and edit Attributes & Claims.
  2. Add a new claim with Name role, Namespace http://schemas.xmlsoap.org/ws/2005/05/identity/claims, Source Attribute, and Source attribute user.assignedroles.
Define the app roles
  1. Go to App registrations, select the Reducto app, and open App roles.
  2. Click Create app role once for each of Owner, Admin, and Member. Set both Display name and Value to the role name.
  3. Set Allowed member types to Users/Groups, add a description, leave the role enabled, and save.
When you assign a user or group to the enterprise application, pick the app role to grant. Assigning a group gives every member of that group the selected Reducto role.

Frequently asked questions

SAML support

Yes. Reducto supports SAML 2.0, with both SP-initiated and IdP-initiated logins. OIDC is also supported.
Guided setup is available for Entra ID (Azure AD), Okta, Google, OneLogin, JumpCloud, Duo, Rippling, and Ping Identity. Any other IdP that supports SAML 2.0 works through the generic SAML integration.
Both values are shown in the guided setup page for your organization. Enter them into your IdP when creating the application (in Entra ID, these are the Reply URL and Identifier fields in Basic SAML Configuration).
No. In Entra ID’s Basic SAML Configuration, only the Identifier (Entity ID) and Reply URL (ACS URL) are required. The Sign on URL is only used when starting login from a bookmark or the My Apps portal tile. You may leave it blank, or set it to your organization’s login URL: https://auth.reducto.ai/saml/{org_slug}/login.
Yes. After completing the setup guide and clicking Finish & Go Live, take your organization’s login URL (https://auth.reducto.ai/saml/{org_slug}/login) and replace /login with /metadata. Navigating to that URL downloads the SP metadata XML, which can be used for a Relying Party Trust configuration.
No. The IdP signing certificate is provided during setup. When your IdP rotates its token signing certificate, update the SAML connection with the new certificate by revisiting the setup page. We recommend configuring certificate expiry notifications in your IdP.

Attributes and provisioning

The SAML response should include:
Yes, for SAML connections. Send a role attribute with the value Owner, Admin, or Member, or put users in groups named role_Owner, role_Admin, or role_Member and include group membership in the SAML response. Users without a recognized role become Members. See Mapping roles from your IdP for per-IdP steps.
Not yet. OIDC connections provision every user as a Member. An Owner or Admin can change roles afterwards from the organization settings page. If role mapping matters for your rollout, configure SAML instead of OIDC.
Yes. Users are provisioned automatically on their first SSO login.
SCIM is available for Okta, Entra ID, OneLogin, JumpCloud, and Ping Identity. Contact your Reducto account team to confirm availability for your organization.

Login behavior

No. Once Enterprise SSO is enabled for your organization, members (and users sharing your organization’s email domain) can only log in through your IdP.
Yes. Both SP-initiated and IdP-initiated logins are supported.
Users with a role that includes the Enterprise SSO permission can configure it from the organization settings page.

Need help?

Contact support@reducto.ai or your Reducto account team for SSO setup assistance.