Single Sign-On lets your team log in to CheckHub with the corporate account they already use every day. No separate CheckHub password to remember, and your own password policy, multi-factor authentication and offboarding rules apply automatically.
This article explains how the setup works. The detailed steps live in a separate article for each identity provider.
What you need
CheckHub connects to two identity providers: Microsoft Entra ID (Azure AD) and Google Workspace. Both are connected over SAML 2.0.
You will need administrator rights in your identity provider, and a test user to try the connection before you roll it out to everyone.
How the setup works
Setting up SSO is an exchange of details between your identity provider and CheckHub. We go first — you can't configure anything until we send you two values.
- You ask us for a connection. Write to your account manager and tell us which identity provider you use, which environment you want SSO for (production, staging, or both), your email domain, and who we should send the details to.
- We send you two values: an ACS URL and an Entity ID. These identify CheckHub to your provider, and they are unique to your connection.
- You create the SAML application in your identity provider using those two values, and you map your users' attributes and groups.
- You send us three things back: your SSO URL, your Entity ID, and your signing certificate.
- We finish the connection and tell you it's ready.
- You test with one user, then assign the rest of your team.
Good to know
Each environment needs its own connection. If you want SSO in both production and staging, we run this process twice.
Group mapping is not optional. CheckHub decides what a user can do from the groups your provider sends. A user whose groups don't match anything in CheckHub can't log in at all. The good news is that you control both sides — your CheckHub groups are yours to edit — so read the attribute and group article before you start.
Next steps
Pick the article for your identity provider:
And read these alongside it:
