Skip to content

Single Sign-On (SSO) Setup

Single Sign-On (SSO) connects your identity provider (IdP) to Kindo through SAML. Settings → SSO appears under Organization for organization Admins. Each organization has one SAML connection.

  1. Open Settings → SSO. Select Create SAML connection if your organization has no connection. Use the existing connection if one is present.

  2. In Service Provider Configuration, use the copy buttons for ACS URL and SP Entity ID. Add these values to your identity provider’s Kindo application.

  3. Configure the application’s SAML attributes.

  4. In Identity Provider (IdP) Configuration, select Upload metadata XML and choose the IdP metadata file. The file imports immediately. To use pasted XML, paste the XML contents and select Import.

    For manual configuration, enter IdP Entity ID, Redirect URL, and the full PEM Signing certificate. Select Save. After import or save, confirm that the certificate shows Valid until <date>.

  5. Assign a pilot user or group to the IdP application. Open Kindo in a private browser window. Select Continue with SAML SSO and enter the pilot user’s email address. Complete sign-in with your identity provider.

  6. If your organization uses the Kindo application tile in your identity provider, test sign-in from that tile too.

  7. If your organization requires SSO, enable SSO Enforcement after the pilot sign-ins succeed. Test sign-in again with enforcement enabled.

Use these exact attribute names. Leave the namespace blank.

AttributeRequirementValue
emailRequired unless the SAML Name ID contains the email addressThe user’s Kindo email address on your organization’s verified domain
givenNameOptional, recommendedThe user’s first name
surnameOptional, recommendedThe user’s last name

Kindo reads the email address from email, with the SAML Name ID as a fallback. If you send both, use the same email address.

Send givenName and surname to populate the user’s display name. The display name falls back to displayName, then the Name ID.

  1. Create a Relying Party Trust in ADFS. Use the SP Entity ID and ACS URL from Kindo’s Service Provider Configuration.

  2. Add a Send LDAP Attributes as Claims rule with these mappings:

    LDAP attributeOutgoing claim
    E-Mail-Addressesemail
    Given NamegivenName
    Surnamesurname
  3. Add a Transform an Incoming Claim rule. Set the incoming claim type to E-Mail Address. Set the outgoing claim type to Name ID and the format to Email. Select Pass through all claim values.

    ADFS claim rule mappings (LDAP attributes to SAML claims)

    ADFS transform claim rule wizard (E-Mail Address to Name ID)

  1. On the Kindo login screen, select Continue with SAML SSO.

  2. Enter your email address. Kindo redirects you to your identity provider.

  3. Complete sign-in with your identity provider.

You can also select the Kindo application tile in your identity provider. Both paths return you to Kindo.

Kindo creates an account on a user’s first SSO sign-in when their email address uses the organization’s verified domain. This is just-in-time provisioning.

Configure IdP Entity ID, Redirect URL, and Signing certificate before enabling enforcement. With SSO Enforcement enabled, organization members must use SSO for sign-in.

  1. Complete the pilot sign-in tests above.

  2. Open Settings → SSO.

  3. Turn on SSO Enforcement.

  4. Test a fresh sign-in in a private browser window.