Before you start with SSO and SCIM
SSO and SCIM aren’t available on every plan. To add them to your team, contact us through the Enterprise form or at hi@ahaslides.com. There is no SSO or SCIM screen in your team settings. You set up your identity provider, and our team completes the AhaSlides side for you:
You need admin access to your identity provider and an AhaSlides team that your members will join.
Connect your identity provider
AhaSlides works with any SAML 2.0 identity provider, such as Okta, and with Microsoft Entra ID.1
Ask us to switch SSO on
Contact us with your team’s name and the email domains you use. We reply with your provider name, a short identifier for your organisation that appears in your SSO addresses.
2
Create the AhaSlides app in your identity provider
For a SAML 2.0 provider, create a SAML app with these values:
You can also download our service provider metadata from
https://presenter.ahaslides.com/p/saml/your-provider-name/metadata.For Microsoft Entra ID, register an application instead. We send you the redirect URI to add to it.3
Send us your identity provider details
For SAML, send the identity provider sign-on URL, the issuer and the X.509 signing certificate, or the metadata file that contains them. If you want first and last names filled in, tell us which attributes carry them.For Microsoft Entra ID, send the tenant ID, the client ID and a client secret.
4
Assign people and test
Assign the app to the people who should use AhaSlides. Once we confirm the connection is live, test it by following the steps in Sign in with SSO.
Link your email domains to your team
SSO works only for email addresses on a domain linked to your team, and we link those domains for you. Send us every domain your members sign in with.- A domain can be linked to one team only.
- Someone whose email is on a domain that isn’t linked can’t sign in through your SSO.
Sign in with SSO
1
Open the SSO page
On the AhaSlides login page, click Log in with SSO.
2
Enter your work email
Type your email address and click Log in. AhaSlides sends you to your organisation’s sign-in page.
3
Sign in with your organisation
After you sign in there, you land in AhaSlides.
Require SSO for your domain
By default, setting up SSO adds a way to sign in; it doesn’t remove the others. Anyone who already has an AhaSlides password can still use it. If your organisation needs SSO to be the only way in, ask us to turn on SSO-only login for your linked domains. It needs a working SSO connection first. Once it’s on, anyone using an email address on a linked domain sees this:
This applies to every address on the linked domain, including people who haven’t joined your team yet.
Set up SCIM user provisioning
SCIM lets your identity provider create, update and deactivate AhaSlides accounts for you. AhaSlides supports SCIM 2.0 for users.1
Ask us for a SCIM token
We generate the token and send it to you. Store it somewhere safe: we keep only a hash of it, so we can’t show it to you again. If you lose it, or it may have been exposed, ask us for a new one.
2
Enter the connection details in your identity provider
3
Map the user attributes
Map the attributes listed under Supported SCIM attributes, then turn on creating, updating and deactivating users. Leave password sync off.
4
Assign users
Assign people or groups to the AhaSlides app. Your identity provider then creates their accounts.
Supported SCIM attributes
Supported SCIM operations
Groups and
DELETE aren’t supported. To take away someone’s access, set active to false, which is what most identity providers send when you unassign a user.
A user created through SCIM joins your team with the Member role. If the email already belongs to an AhaSlides account that isn’t in a team, that account is added to your team instead of a new one being created.
What changes on your team page
While SCIM is on, your identity provider is the place to manage membership. On the team page the Invite button no longer appears, and members can’t edit their own email address in their account settings.Troubleshooting SSO and SCIM
The SCIM connection test returns 401
The token is missing, mistyped or no longer active. Check that it is sent as a bearer token with nothing added around it. If it still fails, ask us for a new token.A provisioned member’s name is wrong or empty
Sendname.givenName and name.familyName. When only displayName is sent, AhaSlides splits it at the first space, which misplaces names with more than two parts.
A member can’t sign in with SSO
Check that the member is assigned to the AhaSlides app in your identity provider and that their email domain is one you asked us to link. If you’ve added a new domain, tell us so we can link it.Frequently asked questions
Can one email domain be linked to two teams?
Can one email domain be linked to two teams?
No. Each domain belongs to a single team, so everyone on that domain signs in to the same team.
Does SCIM delete AhaSlides accounts?
Does SCIM delete AhaSlides accounts?
No. SCIM deactivates an account and signs the member out. Their presentations stay in the account.
I use SSO and forgot my password. What do I do?
I use SSO and forgot my password. What do I do?
You don’t have an AhaSlides password to reset. Sign in with Log in with SSO, and see Change or reset your password for how password reset treats SSO accounts.