Skip to main content
Reducto supports Enterprise SSO, letting your team log in with your identity provider (IdP) credentials. This page covers how setup works and answers common questions from IT and security teams.

How SSO works at Reducto

Users sign in at accounts.reducto.ai. Enterprise SSO is configured per organization through a guided setup page. Once SSO is enabled for your organization, members can no longer log in with other methods such as email/password or magic link. To get started, contact your Reducto account team or support. We will send you a shareable setup link that should guide you through the setup process.

Setup process

1

Request SSO for your organization

Contact your Reducto account team to enable Enterprise SSO for your organization. We can also generate a setup link for the person configuring your IdP, even if they do not have a Reducto account.
2

Follow the guided setup for your IdP

The setup page provides step-by-step guides for Entra ID (Azure AD), Okta, Google, OneLogin, JumpCloud, Duo, Rippling, and Ping Identity, plus a generic guide for any other SAML 2.0 or OIDC provider. It supplies the values to enter into your IdP, including the ACS URL and SP Entity ID.
3

Provide your IdP details

For SAML, you enter your IdP SSO URL, IdP Entity ID, and the token signing certificate. The guide then walks through mapping user attributes and, optionally, roles.
4

Finish and go live

After clicking Finish & Go Live, the setup page shows your organization’s login URL in the form https://auth.reducto.ai/saml/{org_slug}/login.

Frequently asked questions

SAML support

Yes. Reducto supports SAML 2.0, with both SP-initiated and IdP-initiated logins. OIDC is also supported.
Guided setup is available for Entra ID (Azure AD), Okta, Google, OneLogin, JumpCloud, Duo, Rippling, and Ping Identity. Any other IdP that supports SAML 2.0 works through the generic SAML integration.
Both values are shown in the guided setup page for your organization. Enter them into your IdP when creating the application (in Entra ID, these are the Reply URL and Identifier fields in Basic SAML Configuration).
No. In Entra ID’s Basic SAML Configuration, only the Identifier (Entity ID) and Reply URL (ACS URL) are required. The Sign on URL is only used when starting login from a bookmark or the My Apps portal tile. You may leave it blank, or set it to your organization’s login URL: https://auth.reducto.ai/saml/{org_slug}/login.
Yes. After completing the setup guide and clicking Finish & Go Live, take your organization’s login URL (https://auth.reducto.ai/saml/{org_slug}/login) and replace /login with /metadata. Navigating to that URL downloads the SP metadata XML, which can be used for a Relying Party Trust configuration.
No. The IdP signing certificate is provided during setup. When your IdP rotates its token signing certificate, update the SAML connection with the new certificate by revisiting the setup page. We recommend configuring certificate expiry notifications in your IdP.

Attributes and provisioning

The SAML response should include:
Yes. The setup guides include directions for mapping roles from your IdP, including mapping based on group membership.
Yes. Users are provisioned automatically on their first SSO login.
SCIM is available for Okta, Entra ID, OneLogin, JumpCloud, and Ping Identity. Contact your Reducto account team to confirm availability for your organization.

Login behavior

No. Once Enterprise SSO is enabled for your organization, members (and users sharing your organization’s email domain) can only log in through your IdP.
Yes. Both SP-initiated and IdP-initiated logins are supported.
Users with a role that includes the Enterprise SSO permission can configure it from the organization settings page.

Need help?

Contact support@reducto.ai or your Reducto account team for SSO setup assistance.