Administration

# Set up single sign-on with SAML

Let your employees log in to Transportial with your company’s identity provider by adding a SAML configuration for your email domains.

Updated 4 October 2026

**Who can do this:** Role level 1000 or higher.

With single sign-on (SSO), your employees log in to Transportial with the same account they use for email and other company tools, for example Microsoft Entra ID, Okta or Google Workspace. Transportial supports SSO through SAML. You add a configuration that connects your identity provider to your platform for one or more email domains.

## Before you start

* You need someone who can register a new application in your identity provider.
* Have the identity provider's SAML metadata file ready, or its entity ID, sign-on address and signing certificate.

## Add a SAML configuration

1. Open the side menu (☰, top right), choose **Settings** and click the **SAML SSO** tab.
2. Click **Add New SAML Configuration**.
3. Enter a **Name** and, optionally, a **Description**.
4. Under **Allowed Domains**, click **Add Domain** and enter your email domain, for example yourcompany.com. Add every domain your employees use.
5. Under **Identity Provider Information**, upload the identity provider's metadata XML file. The fields are filled in from the file.
6. Or, instead of a file, fill in the **Entity ID**, **Name ID Format**, **Protocol**, the **SSO Services** (each with a **Binding** and **Location**, added with **Add SSO Service**) and the **Signing Certificates** (added with **Add Signing Certificate**).
7. Open the **Service Provider Information** section and click **Download SP Metadata**.
8. Give the downloaded file to your identity provider administrator, who uses it to register Transportial.
9. Switch on **Enable SAML** when both sides are set up.
10. Click **Save**.

## Signing options

* **Signed AuthnRequest Required**: set this to match your identity provider, if it requires signed login requests.
* **Is Request Signed** and **Want Assertions Signed** under **Service Provider Information**: show, for information, whether Transportial signs its requests and expects signed answers. Your identity provider reads the same from the metadata file.

## Test the connection

1. Open a private browser window.
2. Go to the Transportial login page and log in with an email address in one of the allowed domains.
3. Check that you are sent to your identity provider and back into Transportial.
4. Keep your own session in the other window open until it works, so you can correct the configuration.

## Manage configurations

The **SAML Configurations** list shows each configuration's **Name** and whether it **Is Enabled**. Click a row to see its details, **Edit** to change it, or **Remove** to delete it.

Removing or disabling a configuration stops SSO login for its domains straight away. Make sure users have another way to log in first.

## Related articles

* [Manage your sessions, password and two-factor authentication](/en/help/security-settings)
* [Log in and keep your account secure](/en/help/log-in-and-security)
* [Manage users](/en/help/users)

## Still need help?

Our support team is happy to answer any question about Transportial.

[Contact support](/en/contact)[Report an issue](/en/report-issue)

---
Canonical page: https://transportial.com/en/help/saml-single-sign-on
