> ## Documentation Index
> Fetch the complete documentation index at: https://docs.ahaslides.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Set up SSO and SCIM provisioning

> Connect your identity provider to AhaSlides for single sign-on, require SSO for your email domain, and provision team members automatically with SCIM 2.0.

Single sign-on (SSO) lets your team log in to AhaSlides through your organisation's identity provider instead of an AhaSlides password, and SCIM provisioning creates and deactivates their accounts from that same provider. Use them together when your IT team needs one place to control who can reach AhaSlides.

## Before you start with SSO and SCIM

SSO and SCIM aren't available on every plan. To add them to your team, contact us through the [Enterprise form](https://ahaslides.com/enterprise/) or at [hi@ahaslides.com](mailto:hi@ahaslides.com).

There is no SSO or SCIM screen in your team settings. You set up your identity provider, and our team completes the AhaSlides side for you:

| Step | You | AhaSlides |
| - | - | - |
| Connect your identity provider | Create the AhaSlides app in your identity provider and send us its details | Sends your provider name and switches SSO on for your team |
| Link your email domains | Tell us which domains your team signs in with | Links them to your team |
| Require SSO-only login | Ask us to turn it on | Turns it on or off for your linked domains |
| SCIM provisioning | Enter the SCIM URL and token in your identity provider | Generates your SCIM token |

You need admin access to your identity provider and an AhaSlides [team](/teams-and-enterprise/managing-your-team-members) that your members will join.

## Connect your identity provider

AhaSlides works with any SAML 2.0 identity provider, such as Okta, and with Microsoft Entra ID.

<Steps>
  <Step title="Ask us to switch SSO on">
    Contact us with your team's name and the email domains you use. We reply with your **provider name**, a short identifier for your organisation that appears in your SSO addresses.
  </Step>

  <Step title="Create the AhaSlides app in your identity provider">
    For a SAML 2.0 provider, create a SAML app with these values:

    | Field | Value |
    | - | - |
    | Single sign-on URL (ACS URL) | `https://presenter.ahaslides.com/p/saml/your-provider-name/login/callback` |
    | Audience URI (SP entity ID) | The value we send you with your provider name |
    | Name ID | The user's email address |

    You can also download our service provider metadata from `https://presenter.ahaslides.com/p/saml/your-provider-name/metadata`.

    For Microsoft Entra ID, register an application instead. We send you the redirect URI to add to it.
  </Step>

  <Step title="Send us your identity provider details">
    For SAML, send the identity provider sign-on URL, the issuer and the X.509 signing certificate, or the metadata file that contains them. If you want first and last names filled in, tell us which attributes carry them.

    For Microsoft Entra ID, send the tenant ID, the client ID and a client secret.
  </Step>

  <Step title="Assign people and test">
    Assign the app to the people who should use AhaSlides. Once we confirm the connection is live, test it by following the steps in Sign in with SSO.
  </Step>
</Steps>

## Link your email domains to your team

SSO works only for email addresses on a domain linked to your team, and we link those domains for you. Send us every domain your members sign in with.

* A domain can be linked to one team only.
* Someone whose email is on a domain that isn't linked can't sign in through your SSO.

## Sign in with SSO

<Steps>
  <Step title="Open the SSO page">
    On the [AhaSlides login page](https://presenter.ahaslides.com/pages/login), click **Log in with SSO**.
  </Step>

  <Step title="Enter your work email">
    Type your email address and click **Log in**. AhaSlides sends you to your organisation's sign-in page.
  </Step>

  <Step title="Sign in with your organisation">
    After you sign in there, you land in AhaSlides.
  </Step>
</Steps>

The first time someone signs in with SSO, AhaSlides creates their account if they don't have one and adds them to your team with the **Member** role. They never set an AhaSlides password.

## Require SSO for your domain

By default, setting up SSO adds a way to sign in; it doesn't remove the others. Anyone who already has an AhaSlides password can still use it. If your organisation needs SSO to be the only way in, ask us to turn on SSO-only login for your linked domains. It needs a working SSO connection first.

Once it's on, anyone using an email address on a linked domain sees this:

| Where | What they see |
| - | - |
| Log in, sign up and forgot password pages | A window titled **Your organisation requires single sign-on** after they enter their email. **Continue with SSO** takes them to the SSO page; **Use a different email** clears the field. |
| The SSO page | The message "Your organisation requires single sign-on. Please continue below to sign in." with their email filled in |
| Account settings | No **Password** section, and their email address can't be edited |

This applies to every address on the linked domain, including people who haven't joined your team yet.

## Set up SCIM user provisioning

SCIM lets your identity provider create, update and deactivate AhaSlides accounts for you. AhaSlides supports SCIM 2.0 for users.

<Steps>
  <Step title="Ask us for a SCIM token">
    We generate the token and send it to you. Store it somewhere safe: we keep only a hash of it, so we can't show it to you again. If you lose it, or it may have been exposed, ask us for a new one.
  </Step>

  <Step title="Enter the connection details in your identity provider">
    | Setting | Value |
    | - | - |
    | SCIM base URL | `https://presenter.ahaslides.com/api/scim/v2` |
    | Authentication | Bearer token, sent as `Authorization: Bearer your-token` |
    | Unique identifier | `userName` |
  </Step>

  <Step title="Map the user attributes">
    Map the attributes listed under Supported SCIM attributes, then turn on creating, updating and deactivating users. Leave password sync off.
  </Step>

  <Step title="Assign users">
    Assign people or groups to the AhaSlides app. Your identity provider then creates their accounts.
  </Step>
</Steps>

### Supported SCIM attributes

| SCIM attribute | Used for |
| - | - |
| `userName` | The member's email address. It identifies the user and is stored in lower case. |
| `name.givenName`, `name.familyName` | First and last name |
| `displayName` | Used for the name only when `name` isn't sent: the first word becomes the first name and the rest the last name |
| `active` | `true` keeps the account active; `false` deactivates it and signs the member out |
| `externalId` | Returned unchanged in the response |

### Supported SCIM operations

| Method | Endpoint | What it does |
| - | - | - |
| `GET` | `/Users` | Lists your team's users. Accepts `filter=userName eq "name@example.com"`, `startIndex` and `count` (10 by default). |
| `GET` | `/Users/{id}` | Returns one user |
| `POST` | `/Users` | Creates a user |
| `PATCH` | `/Users/{id}` | Updates some attributes, for example `active` |
| `PUT` | `/Users/{id}` | Replaces a user's attributes |

Groups and `DELETE` aren't supported. To take away someone's access, set `active` to `false`, which is what most identity providers send when you unassign a user.

A user created through SCIM joins your team with the **Member** role. If the email already belongs to an AhaSlides account that isn't in a team, that account is added to your team instead of a new one being created.

### What changes on your team page

While SCIM is on, your identity provider is the place to manage membership. On the team page the **Invite** button no longer appears, and members can't edit their own email address in their account settings.

## Troubleshooting SSO and SCIM

### The SCIM connection test returns 401

The token is missing, mistyped or no longer active. Check that it is sent as a bearer token with nothing added around it. If it still fails, ask us for a new token.

### A provisioned member's name is wrong or empty

Send `name.givenName` and `name.familyName`. When only `displayName` is sent, AhaSlides splits it at the first space, which misplaces names with more than two parts.

### A member can't sign in with SSO

Check that the member is assigned to the AhaSlides app in your identity provider and that their email domain is one you asked us to link. If you've added a new domain, tell us so we can link it.

## Frequently asked questions

<AccordionGroup>
  <Accordion title="Can one email domain be linked to two teams?">
    No. Each domain belongs to a single team, so everyone on that domain signs in to the same team.
  </Accordion>

  <Accordion title="Does SCIM delete AhaSlides accounts?">
    No. SCIM deactivates an account and signs the member out. Their presentations stay in the account.
  </Accordion>

  <Accordion title="I use SSO and forgot my password. What do I do?">
    You don't have an AhaSlides password to reset. Sign in with **Log in with SSO**, and see [Change or reset your password](/account-management/change-or-reset-your-password) for how password reset treats SSO accounts.
  </Accordion>
</AccordionGroup>

**Have a question?**

Contact our support team — if you're logged in, use the chat bubble in the bottom-right of your dashboard; otherwise [contact us here](https://ahaslides.com/contact-us/) or email [hi@ahaslides.com](mailto:hi@ahaslides.com).

Want to connect with other users? Join the [AhaSlides community](https://community.ahaslides.com/) to share tips, request features, and see how others engage their audiences.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.