SAML Setup

Last updated: July 28, 2026

SAML is a standard that allows your company's login system to verify your identity to other applications, enabling single sign-on (SSO). Below you'll find detailed setup instructions for Microsoft and Okta SAML configurations.


Eligibility

SAML authentication eligibility is evaluated based on your account tier and on a case-by-case basis. Contact your Strategic Account Manager to confirm eligibility and begin setup.


Microsoft SAML Setup

Before you start, contact Bridgit Support to get your Reply URL and Identifier (Entity ID) — you'll need these in Step 10.

Create the app

  1. In Microsoft Azure, open Enterprise Applications

  2. Click + New Application, then + Create your own application

  3. Enter Bridgit as the name

  4. Select Integrate any other application you don't find in the gallery

  5. Click Create

Configure Single Sign-On

  1. Open the app and go to Single Sign-On, then select SAML

  2. Copy and save the Login URL and Logout URL — you'll send these to Bridgit later

  3. Click Edit on Basic SAML Configuration and enter:

Field

Value

Identifier (Entity ID)

Provided by Bridgit

Reply URL

Provided by Bridgit

  1. Leave Attributes & Claims as default

Download the certificate

  1. Download the Base64 SAML Certificate under the SAML Signing Certificate section (refresh the page if the certificate doesn't appear)

Finish setup

  1. Under Users and Groups, assign the appropriate users or groups

  2. Send the following to Bridgit Support:

    • Base64 SAML Certificate

    • Login URL

    • Logout URL


Okta SAML Setup

Before you start, make sure you have access to the Okta admin panel, then contact Bridgit Support to get your Single Sign-On URL and Audience URI — you'll need these in Step 6.

Create the app

  1. In the Okta admin panel, go to Applications > Applications

  2. Click Create App Integration

  3. Select SAML 2.0 and click Next

  4. Enter Bridgit as the app name (add a logo if desired) and click Next

Configure SAML settings

  1. Enter the Single Sign-On URL provided by Bridgit

  2. Enter the Audience URI provided by Bridgit

  3. Set Name ID format to EmailAddress

  4. Set Application username to Email

Add an attribute statement

  1. Under Attribute Statements (optional), add the following and click Next:

Name

Name Format

Value

email

Basic

user.email

Finish setup

  1. Select I'm an Okta customer if prompted, then click Finish

  2. Go to the Sign On tab and send Bridgit Support one of the following:

    • The Metadata URL (easiest), or

    • The Sign On URL + downloaded Signing Certificate (recommended)

  3. Assign the app to the appropriate users or groups

Important: Bridgit does not support IdP-initiated logins. The default Okta chicklet will not work. You can simulate the Okta chicklet using an Okta Bookmark App with your account's direct link URL. Instructions from Okta.