​
Supported features

  • IdP-initiated Single Sign-On, initiated via Entra ID
  • SP-initiated Single Sign-On, initiated from Chalk
  • Push group and user provisioning via SCIM, initiated from Entra ID

For details about Chalk’s authentication capabilities, see SSO and SAML.


​
Customers with self-hosted web dashboards

For customers whose self-hosted deployments include a full API server and frontend deployment via helm, this page covers only part of the SAML setup. After completing this guide, refer to the Cloud Auth documentation to complete setup.

If your Chalk web dashboard is not https://chalk.ai, check your team’s dashboard for the correct values. These can be found under Single Sign-On in the team settings:

  • Single Sign-On URL: This should start with your custom URL and not chalk.ai, but retain the same URL path.
  • Audience URI: This should start with your custom URL and not chalk.ai.
  • Chalk’s SAML Certificate is regenerated for each custom web dashboard. If your team did not generate this themselves, contact Chalk for support.

​
Setup steps

All details and controls are on your team’s Single Sign-On page, under the team settings.

​
Set up an Entra ID SAML application

  1. Navigate to your Entra ID admin dashboard
  2. From “Enterprise Apps”, find and select “New Application”
    • Select “Create your own application”
    • Name this application (“Chalk”, for example)
    • Select “Integrate any other application you don’t find in the gallery (Non-gallery)”
  3. Configure SAML
    • In the application sidebar, find Single Sign-on
    • Select SAML as the login method
  4. Set Up SAML (Basic SAML Configuration)
    • Identifier (Entity ID): https://chalk.ai/api/saml/metadata.xml
    • Reply URL (Assertion Consumer Service URL): https://chalk.ai/api/auth/login/saml
    • Sign-On Url: https://chalk.ai/login
    • Relay State: Leave blank
    • Logout URL: https://chalk.ai/api/auth/signout
  5. Set Up SAML (Attributes & Claims): This section will depend on your own Entra ID setup and what attributes are in use. However, Chalk requires the following to be set:
    • givenname
    • surname
    • Unique User Identifier: This should match your user’s primary email address attribute
  6. Set Up Application: No inputs are necessary in this section. Download the Federation Metadata XML, which you need in the next section.
  7. Test single sign-on: You cannot do this until you connect Chalk to your application in the next section.

​
Connect Chalk to your SAML application

You can connect your Entra ID application with Chalk from Single Sign-On in the team settings. In the SAML Configurations section, select Add configuration. To integrate your SAML application with Chalk, select Or upload metadata XML and upload the Federation Metadata XML from the previous section. The form fills in:

  • Issuer
  • Login URL
  • Certificate

​
Next steps

After you verify that you can log in to Chalk from your Entra ID application, you can: