Security
Setting up Single-Sign On with SAML
Chalk supports Single Sign-On (SSO) and is compatible with any Identity Provider that supports SAML 2.0, such as:
Chalk supports Identity Provider (IdP)-initiated login and Service Provider (SP)-initiated login. SP-initiated login uses the well-known email domains that your team submits.
Chalk also supports just-in-time provisioning, so users can access the dashboard even if an owner has not explicitly invited them. Users who log in through SSO with this provisioning have the Viewer role.
For customers whose self-hosted deployments include a full API server and frontend deployment via helm, this page covers only part of the SAML setup. After completing this guide, refer to the Cloud Auth documentation to complete setup.
The examples on this page come from an example environment on the https://chalk.ai site. The values on your deployment’s Single Sign-On page differ from the examples. Use the values on your own page when you set up SAML applications.
Team owners configure SSO under Single Sign-On in the team settings. This page includes the details that your identity provider needs to set up a SAML application, the form to submit your SAML application’s certificate and other details to Chalk, and the section to register the well-known email domains that can access your SAML application.
The details that you need to set up a SAML application in your identity provider are in the SAML Setup Details section at the bottom of the page:
In your SAML application, configure the following:
For detailed steps for a specific identity provider, follow these guides:
After you create a SAML application in your identity provider, submit its details to Chalk. In the SAML Configurations section, select Add configuration and enter the following details:
To make a configuration the one that Chalk uses by default, select Use as the primary SSO configuration.
If your identity provider provides a metadata XML file, select Or upload metadata XML instead of entering the issuer, login URL, and certificate. The file contains all three.
After you submit the configuration, the SAML application is ready to use and you can test it from your identity provider. The configuration appears in the SAML Configurations list, where you can edit or delete it:
Chalk supports sign in via SSO from the dashboard’s login page if your email domain is registered with Chalk. You can register email domains after you configure a SAML application for your team.
To register your domain with Chalk:
The login page has an email field and a Sign in with SSO button: