Single sign on (SSO) allows Tropic users to log in using an SSO provider, such as Okta, Microsoft Entra, or OneLogin, without managing separate passwords. This enhances security and simplifies access management.
This guide provides step-by-step instructions for setting up SSO with Tropic, including prerequisites, configuration steps, and key limitations.
Once your SSO is set up, you can log in from your SSO provider (IdP-initiated) or the Tropic login page (SP-initiated). Keep in mind that you won’t be able to set a Tropic password.
Prerequisites
Role required: Owner
An active SSO provider (Okta, Microsoft Entra, OneLogin, etc.).
Access to Tropic's Login Configuration settings.
Your organization slug (found in Tropic’s SSO settings).
Steps to Connect SSO with Tropic
To enable SSO, you need to register Tropic as an app in your SSO provider and configure the necessary settings.
Navigate to Settings → Login Configuration in Tropic.
Register Tropic as an app within your SSO provider (Okta, Microsoft Entra, OneLogin).
Configure the necessary SAML settings (outlined in the provider-specific sections below).
Download and send your SSO certificate and Login URL to Tropic Support for verification.
Assign users or groups to the Tropic app within your SSO provider.
Configuring SSO by Provider
Setting Up SSO with Okta
Sign in to the Okta Admin Console.
Navigate to Applications > Applications > Create App Integration.
Select SAML 2.0 and click Next.
In General Settings, enter an app name (e.g., Tropic) and click Next.
Save the configuration and download the SAML Signing Certificate.
Send the certificate and Login URL to Tropic Support.
Note: In the provided example, [CUSTOMER-ID] refers to the unique identifier associated with your organization within Tropic's system. For instance, if your organization's name in Tropic is "Acme Corp," then the Sign-On URL would be "https://app.tropicapp.io/login?org=acme-corp". This ensures that the authentication process is tailored to your organization's specific account within Tropic.
Setting Up SSO with OneLogin
Sign in to the OneLogin Admin Portal.
Navigate to Applications > Applications > Add App.
Search for "SAML Custom Connector (Advanced)" and select it.