SAML SSO Setup

SAML SSO Setup

Setting up SAML Single Sign-On (SSO) with ThoughtRiver

We support SAML 2.0 Single Sign-On (SSO) integration, allowing your users to securely log in to ThoughtRiver using your existing identity provider (IdP). In this setup, ThoughtRiver acts as the Service Provider (SP), and your organization’s identity platform (e.g., Azure AD, Okta, Ping Identity, etc.) acts as the Identity Provider (IdP).
Note: All users logging in via SAML must already exist in the ThoughtRiver platform. 

Information Required from You

To set up the integration, we need the following:
  1. X.509 Public Certificate in PEM format
  2. SAML Login URL (the redirect for authentication requests)
  3. SAML Logout URL (optional)
  4. Request Signing Details:
    1. Whether your IdP requires SAML request signing
    2. Signature algorithm (e.g., RSA-SHA256)
    3. Digest method
    4. Binding method (Redirect or POST)
  5. Email Domain(s) of users who will use SAML

What We'll Provide

Once we receive the required information, we’ll configure the integration and provide you with the following:
  1. Assertion Consumer Service (ACS) URL (Callback URL):
  2. Entity ID (SP Issuer)

Next Steps

  1. Share the required information listed above with your ThoughtRiver representative.
  2. We’ll set up the connection and test SSO with a user from your domain.
  3. Once confirmed, your users will be able to log in via your identity provider.
If you have any questions or experience issues during setup, please contact our support team or your ThoughtRiver Customer Success Manager.

    • Related Articles

    • Microsoft Entra (Azure AD) SSO Setup

      Setting up Microsoft Entra (Azure AD) SSO with ThoughtRiver ThoughtRiver supports integration with Microsoft Entra ID (formerly Azure AD) for Single Sign-On (SSO). This guide provides the steps your technical team needs to follow to configure a new ...
    • Accessing multiple tenants

      If you have been setup as a user on more than one tenant, you will use the same email and password to access both tenants. Simply enter your email address and password on the login page, and then you will see a tenant selection screen (like below) ...