Set Up SSO

Single sign-on — including attribute mapping and SCIM provisioning — is available on the Enterprise plan. On other plans, members sign in with a social login or an email and password.

Single sign-on lets your team sign in to Markup AI with your identity provider (IdP). Setup is self-service: you exchange metadata with your IdP, then confirm how Markup AI reads group membership.

You can add more than one connection — for example SAML for your parent company and OIDC for an acquired subsidiary. Each connection has its own configuration.

What you need

  • The Administrator role in your organization.
  • Access to your IdP’s admin console (Okta, Microsoft Entra ID, Google Workspace, JumpCloud, ADFS, PingFederate, or any SAML 2.0 / OIDC provider).

Add a connection

1

Open Single Sign-On settings

In the console, go to Single Sign-On. You’ll see any existing connections and their status.

Single Sign-On connections list with JumpCloud and Azure AD connections
The Single Sign-On & Provisioning page lists every connection, its protocol, verified domains, and status.
2

Create the connection

Select New connection, choose SAML or OIDC, and give it a friendly name your team will recognize. Select Continue to setup — the IdP setup form opens in a new browser tab.

New SSO connection dialog with SAML and OIDC options
Pick a strategy and name the connection.
3

Exchange metadata with your IdP

In the hosted form, pick your provider for step-by-step instructions. You’ll create an application in your IdP and exchange metadata — copy the Single Sign-On URL and Audience URI into your IdP, and provide your IdP’s metadata back. This step only configures the connection between your IdP and Markup AI; no user data changes yet.

Hosted SSO setup showing Okta instructions and the SP metadata URLs
The guided setup walks you through your specific provider — here, Okta — and gives you the URLs to paste into it.

No provider listed? Choose Custom SAML (or OIDC) and enter the connection details by hand.

4

Set the sign-in domains

Back in the console, open the connection and add the email domains that should sign in through it on the Domains tab. Users with a matching domain are routed to this connection.

Connection detail page with the Domains tab selected and a verified domain
Add and verify the domains that route users to this connection.
5

Map your groups

On the connection’s Attribute mapping tab, tell Markup AI which claim carries group membership and how to read it. This is what turns your IdP’s groups into Markup AI groups — see Attribute Mapping.

Editing a connection later

Open any connection from Single Sign-On to change its domains, attribute mapping, or SCIM settings. To re-run the IdP metadata exchange, use the connection’s Actions menu — it reopens the hosted setup form for the existing connection rather than creating a new one.

Next steps