SSO is an Enterprise feature. Contact sales to enable it for your organization.
How it works
- You configure your SAML identity provider to trust Zwiron as a service provider
- You configure Zwiron with your IdP’s metadata URL or entity ID
- When a user from your domain logs in to Zwiron, they are redirected to your IdP to authenticate
- Your IdP returns a SAML assertion to Zwiron, confirming the user’s identity
- Zwiron creates or updates the user’s account and logs them in
Configuration
In your identity provider:- Create a new SAML application
- Set the ACS URL (Assertion Consumer Service URL) to:
- Set the Entity ID / Audience to:
- Map the following attributes:
email→ user’s email addressname(optional) → user’s display name
- Go to Settings → SSO
- Enter your IdP’s Metadata URL (preferred) — Zwiron fetches the configuration automatically, or enter the Entity ID and certificate manually
- Click Save and test to verify the connection
Domain enforcement
Enable Enforce SSO to require that all users with your domain (e.g.@yourcompany.com) log in via SSO. Users who previously had password accounts will be required to use SSO from that point on.
Just-in-time provisioning
When SSO is enabled, users who successfully authenticate via your IdP are automatically created in Zwiron if they don’t exist yet (JIT provisioning). They are assigned the Viewer role by default. An admin can then change their role in Settings → Team.Supported providers (tested)
- Okta
- Azure Active Directory / Microsoft Entra ID
- Google Workspace (SAML)
- OneLogin
- JumpCloud
- Ping Identity
- Any SAML 2.0-compliant IdP