Set up single sign-on with SAML
Let your employees log in to Transportial with your company’s identity provider by adding a SAML configuration for your email domains.
Updated October 4, 2026
With single sign-on (SSO), your employees log in to Transportial with the same account they use for email and other company tools, for example Microsoft Entra ID, Okta or Google Workspace. Transportial supports SSO through SAML. You add a configuration that connects your identity provider to your platform for one or more email domains.
Before you start
- You need someone who can register a new application in your identity provider.
- Have the identity provider's SAML metadata file ready, or its entity ID, sign-on address and signing certificate.
Add a SAML configuration
- Open the side menu (☰, top right), choose Settings and click the SAML SSO tab.
- Click Add New SAML Configuration.
- Enter a Name and, optionally, a Description.
- Under Allowed Domains, click Add Domain and enter your email domain, for example yourcompany.com. Add every domain your employees use.
- Under Identity Provider Information, upload the identity provider's metadata XML file. The fields are filled in from the file.
- Or, instead of a file, fill in the Entity ID, Name ID Format, Protocol, the SSO Services (each with a Binding and Location, added with Add SSO Service) and the Signing Certificates (added with Add Signing Certificate).
- Open the Service Provider Information section and click Download SP Metadata.
- Give the downloaded file to your identity provider administrator, who uses it to register Transportial.
- Switch on Enable SAML when both sides are set up.
- Click Save.
Signing options
- Signed AuthnRequest Required: set this to match your identity provider, if it requires signed login requests.
- Is Request Signed and Want Assertions Signed under Service Provider Information: show, for information, whether Transportial signs its requests and expects signed answers. Your identity provider reads the same from the metadata file.
Test the connection
- Open a private browser window.
- Go to the Transportial login page and log in with an email address in one of the allowed domains.
- Check that you are sent to your identity provider and back into Transportial.
- Keep your own session in the other window open until it works, so you can correct the configuration.
Manage configurations
The SAML Configurations list shows each configuration's Name and whether it Is Enabled. Click a row to see its details, Edit to change it, or Remove to delete it.
Removing or disabling a configuration stops SSO login for its domains straight away. Make sure users have another way to log in first.