Integrations & API

Single sign-on

SAML and OIDC on every plan, mapped to Briesa roles from your IdP's groups.

JBJacob Brownv1.1

SAML and OIDC single sign-on ships on every plan, so your team signs in with the identity provider you already run.

Setting it up

  1. Choose the protocol

    SAML 2.0 or OIDC, whichever your identity provider prefers. Both are supported equally.

  2. Exchange metadata

    Register Briesa in your IdP and hand back the metadata or the discovery endpoint. We'll confirm the mapping for names, emails and groups.

  3. Map roles

    IdP groups map to Briesa roles, so joiners and leavers are handled where you already handle them.

  4. Enforce

    Once the mapping is verified, switch the organisation to SSO-only and password sign-in stops being an option.

What SSO covers