Skip to main content

SSO - Fast and Convenient Login for Employees

Simplify the access to Frontify for all your employees by using SSO (Single Sign-On).

Updated this week

SSO is a fast and convenient way to log in for all of your colleagues. With Single Sign-On, you can give automatic viewing access to all (or parts of) your company's employees. You don't need to manage their access to Frontify, nor do users have to create a profile with a new password to remember. When activated, the login page shows an additional login button above the standard login form.

Certificate Management

Availability

SSO is available for Enterprise plans. Ensure that your system supports the SAML 2.0 standard or OpenID Connect (OIDC). Please get in touch with us for other SSO connectors., but note that we only support SP-initiated SSO.


SAML Configuration

You need the following information to configure SSO for your account:

  • Entity ID

  • SSO Service URL

  • Certificate (x509)

Within the Basic SAML Configuration please add those URLs and replace DOMAIN with your current Frontify URL.

  • Identifier (SP Entity ID): https://DOMAIN/api/auth/saml/metadata/

  • Reply URL (ACS URL): https://DOMAIN/api/auth/saml/acs/

  • Sign on URL: https://DOMAIN/api/auth/saml/

  • Logout URL: https://DOMAIN/api/auth/saml/sls/

The following fields must be part of the SSO request response:

  • Name ID Format: EmailAddress

  • Application Username: Email

including the following attributes:

  • User.email

  • User.FirstName

  • User.LastName

  • User.Groups (optional)


OpenID Connect Configuration

You need the following information to configure OpenID Connect SSO for your account.

  • Authorization URL

  • Access Token URL

  • Client ID

  • Client Secret

  • Scopes*

  • Public Key Source (URL or JSON)

* Mandatory Scopes: openid profile email

* Optional Scope: roleNames (for SSO group mapping)

Tips and Reminders

  • Ensure that the certificates in your metadata file have an updated validity period to prevent authentication issues.

  • Regularly check for updates to the active SP certificate if your organization’s security policies mandate certificate rotation.

  • Refer to Frontify documentation for troubleshooting if errors occur during the configuration process.

  • If users see errors about their account being "disabled," this may indicate SSO force is enabled and they need to contact their account admin to be unlocked in Access Management.


Finally, you can decide which Style Guides/Projects SSO users should get viewing access to and which page users are pointed to upon login. You can redirect into your primary Style Guide or the dashboard (default).


Appendix:

Did this answer your question?