# Single-Sign On (SAML)
source: https://docs.chalk.ai/docs/sso-saml

## Setting up Single-Sign On with SAML

Chalk supports Single Sign-On (SSO) and is compatible with
any Identity Provider that supports SAML 2.0, such as:

- Okta
- Azure Entra ID
- Google
- JumpCloud

### Supported features

Chalk supports Identity Provider (IdP)-initiated login and Service Provider (SP)-initiated login.
SP-initiated login uses the well-known email domains that your team submits.

Chalk also supports just-in-time provisioning, so users can access the dashboard even if an owner
has not explicitly invited them. Users who log in through SSO with this provisioning have the Viewer role.

### Customers with self-hosted web dashboards

For customers whose self-hosted deployments include a full API server and frontend deployment via helm,
this page covers only part of the SAML setup. After completing this guide, refer to
the Cloud Auth documentation to complete setup.

The examples on this page come from an example environment on the https://chalk.ai
site. The values on your deployment's Single Sign-On page differ from the examples. Use the values
on your own page when you set up SAML applications.

### Setup steps

Team owners configure SSO under Single Sign-On in the team settings. This page includes the details
that your identity provider needs to set up a SAML application, the form to submit your SAML application's
certificate and other details to Chalk, and the section to register the well-known email domains that can
access your SAML application.

### Identity provider setup

The details that you need to set up a SAML application in your identity provider are in the
SAML Setup Details section at the bottom of the page:

In your SAML application, configure the following:

- The main assertion subject is the email.
- Assertions are signed. Chalk requires signed assertions, but they do not need to be encrypted with the Chalk certificate.

For detailed steps for a specific identity provider, follow these guides:

- Okta
- Azure Entra ID

### Chalk setup

After you create a SAML application in your identity provider, submit its details to Chalk.
In the SAML Configurations section, select Add configuration and enter the following details:

- Name: A Chalk-internal name that you choose to reference this application. Your identity provider does not provide it.
- Identity Provider Type: Okta, Azure AD, OneLogin, or Other.
- Issuer
- Login URL
- Logout URL: Optional. This might be the same as the Login URL.
- Certificate: The signing certificate from your identity provider.

To make a configuration the one that Chalk uses by default, select Use as the primary SSO configuration.

If your identity provider provides a metadata XML file, select Or upload metadata XML instead of entering
the issuer, login URL, and certificate. The file contains all three.

After you submit the configuration, the SAML application is ready to use and you can test it
from your identity provider. The configuration appears in the SAML Configurations list, where you can edit or delete it:

### Sign in via SSO

Chalk supports sign in via SSO from the dashboard's login page if your
email domain is registered with Chalk. You can register email domains after you configure a SAML application
for your team.

To register your domain with Chalk:

- Open your team's Single Sign-On page.
- In the Email Domains section, select Add domain. Enter a domain that your team uses and select the SAML
configurations that it redirects to. If you select multiple configurations, users choose which one to use
from the login page.
- Chalk Support reviews the submitted domain. A clock icon marks a domain that is pending review, and a check mark
marks an approved one. After a domain is approved, emails that match it redirect to your team's configured SAML applications.

The login page has an email field and a Sign in with SSO button:





