Single sign-on (SSO)
Single sign-on (SSO)
Trebellar supports Single Sign-On (SSO) so your team can log in using your organization’s existing identity provider (IdP), such as Okta, Azure AD, OneLogin, or any standards-based OIDC or SAML provider.
Setting up SSO is a short back-and-forth between your team and Trebellar: you configure a new app integration with your identity provider, share a few connection details with us, and we complete the setup on our end.
Before you start
Make sure you have the following ready:
- Admin access to your identity provider (e.g., Okta, Azure AD, OneLogin).
- Your Trebellar Org ID — provided by your Trebellar account rep.
- Admin access to your Trebellar workspace — needed later to configure how Trebellar handles SSO sign-in (see Configuring SSO login behavior below). This step is self-service and doesn’t require anything from Trebellar.
What to expect
Here’s the process end to end. Most of the work happens on your identity provider’s side — Trebellar’s part is minimal once we have your credentials.
- Create a new app integration with your identity provider.
- Assign the right users or groups to the app.
- Copy your connection details (domain, client ID, and secret) and send them to your Trebellar account rep.
- Trebellar completes the connection on our end.
- In Trebellar, configure how you want SSO to handle sign-in for users who don’t yet exist in your org.
Configuration reference
Trebellar supports both OIDC and SAML. Use whichever your identity provider and internal policy prefer — most customers use OIDC.
OIDC
Values to enter in your identity provider:
What you’ll send to Trebellar:
Authorize and token paths vary by identity provider. Please include your provider’s authorize path and token path (from your provider’s OAuth/OIDC endpoint documentation) when you send us your connection details, so we can complete the connection correctly.
SAML
Values to enter in your identity provider:
What you’ll send to Trebellar:
Setting up your identity provider
In your identity provider’s admin console:
- Create a new app integration (choose OIDC or SAML, depending on which your organization uses — see Configuration reference above).
- Enter the redirect URIs and other values listed above for the protocol you’re using.
- Assign the people or groups who should have SSO access to Trebellar.
- Save the integration, then collect the connection details you’ll need to send to Trebellar (see below).
The exact screens and terminology vary by provider — consult your provider’s own documentation for the specific steps. If you’re using Okta specifically, we also have a dedicated Okta setup guide with a full walkthrough.
Connecting to Trebellar
Once your identity provider is configured, send the following to your Trebellar account rep (or the address provided in your setup email):
- Domain (e.g.,
yourcompany.idp.com) - Client ID
- Client Secret
- Authorize path and token path for your provider’s OAuth/OIDC endpoints
Trebellar will complete the connection on our end and confirm when SSO is live for your org.
Never send your Client Secret over email. Send it to your account rep via a secure channel instead.
Configuring SSO login behavior in Trebellar
After SSO is enabled, you can control what happens when someone signs in through your identity provider but doesn’t already have an account in your Trebellar org. This is configured entirely on your end — no need to involve Trebellar.
To get there:
- Log into Trebellar with an admin account.
- Go to Settings > Security > SSO.
- Choose one of the following options for SSO login behavior.
- Click Save SSO Settings.
If you’re unsure which option fits your organization, Only existing users is the safest default, and you can change it at any time.
Need help?
If you run into any issues while setting up your identity provider or gathering your connection details, reach out to your account rep — we’re happy to help at any stage of the process.