Skip to content
digitalsign.co

Single sign-on

People with your company email sign in through your identity provider. Available on the Enterprise plan.

How it works

  • You connect one identity provider using OpenID Connect (Google Workspace, Microsoft Entra ID, Okta and most modern providers) or SAML 2.0.
  • You list your company email domains and prove you own each one with a DNS TXT record. Only people with an address on a verified domain can sign in through your provider.
  • When someone types their company email on the sign-in page, they are sent to your provider. Their first sign-in adds them to your organization with the default role you choose; you can change it later or let SCIM manage roles.
  • Optionally, require single sign-on: email sign-in links stop working for your verified domains, so leavers lose access as soon as you disable them in your provider.
  • Multi-factor authentication is handled by your provider. Sign-ins appear in the audit log with the method used.

Before you start

In DigitalSign, open Settings → Security as an owner or admin. The page shows the values your provider needs:

ValueUsed for
https://app.digitalsign.co/api/auth/sso/callbackOIDC redirect URI (sign-in redirect URI)
https://app.digitalsign.co/api/auth/saml/acsSAML Assertion Consumer Service (ACS / reply URL)
https://app.digitalsign.co/api/auth/saml/metadata/<your organization id>SAML entity ID (audience) and metadata URL; the exact value is on the Security page

If you use a white-label custom domain, the Security page shows these URLs on your domain instead.

Okta (OIDC)

  1. In the Okta admin console, go to Applications → Create App Integration, choose OIDC - OpenID Connect and Web Application.
  2. Set the Sign-in redirect URI to the callback URL above. Grant type: Authorization Code.
  3. Assign the people or groups who should have access.
  4. Copy the Client ID and Client secret. Your issuer URL is your Okta domain, for example https://acme.okta.com.
  5. In DigitalSign, choose OpenID Connect, paste the issuer URL, client ID and secret, enter your email domains and save.

Microsoft Entra ID (OIDC)

  1. In the Entra admin center, go to App registrations → New registration. Supported account types: this organizational directory only.
  2. Add a Web redirect URI: the callback URL above.
  3. Under Certificates & secrets, create a client secret and copy its value.
  4. Your issuer URL is https://login.microsoftonline.com/<tenant id>/v2.0. The client ID is the application (client) ID on the overview page.
  5. Under Token configuration, add the optional email claim to the ID token.
  6. Enter the values in DigitalSign and save.

Google Workspace (OIDC)

  1. In Google Cloud console, open APIs & Services → Credentials → Create credentials → OAuth client ID, type Web application. On the consent screen, choose Internal so only your Workspace can sign in.
  2. Add the callback URL above as an authorized redirect URI.
  3. Issuer URL: https://accounts.google.com. Copy the client ID and secret into DigitalSign.

Any SAML 2.0 provider

  1. Create a SAML application in your provider. Use the ACS URL and entity ID from the Security page (or import the metadata URL).
  2. Name ID format: email address. Assertions must be signed.
  3. Send the user's email as the Name ID or in an email attribute. A displayName attribute, if present, is used for their name.
  4. In DigitalSign, choose SAML 2.0 and paste your provider's SSO URL (entry point) and signing certificate.

Verify your domains

For each domain, add the TXT record shown on the Security page to your DNS, then click Check DNS. Single sign-on starts working once at least one domain is verified. Public email domains such as gmail.com can't be used.

Troubleshooting

  • “isn't in a domain this organization has verified”: the email your provider sent doesn't match a verified domain. Check which email claim your provider sends.
  • “Your email isn't verified with your identity provider”: your OIDC provider marked the email as unverified.
  • “deactivated by your identity provider”: SCIM deactivated this person; reactivate them in your provider.
  • Locked out because your provider is down while single sign-on is required? Contact [email protected] from an owner's address and we'll help after verifying your identity.