It's a metadata exchange. Your tenant publishes IdP metadata at {issuer}/v1/idp/saml/metadata (SSO URL: {issuer}/v1/idp/saml/sso) — point your SP at it, or configure the SSO URL and certificate by hand. In the other direction, paste your SP's metadata into the console and it pre-fills the entity ID, ACS URLs and certificates. Attribute mapping shapes the assertion your SP expects.
Confirmed patterns include Salesforce, Google Workspace, Slack, Atlassian Cloud, GitHub Enterprise, ServiceNow, Zoom, Zendesk and Dropbox Business — and any other SAML 2.0 SP
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article