Skip to main content

SAML Single Sign-On

Learn what SAML SSO is, why it matters, and how to get started with single sign-on for your Tomba workspace.

Written by Tomba.io Team

What Is Single Sign-On (SSO)?

Single Sign-On lets your team sign in to Tomba using the same login they already use for other company tools — like Google Workspace, Okta, or Microsoft Azure AD. Instead of creating a separate password for Tomba, everyone signs in through your company's identity provider.

[Image: sso_settings_overview.png] — Upload this image


🎯 Why Use SSO?

  • One login for everything — Your team uses the same credentials they already know. No more forgotten passwords.

  • Centralized access control — When someone leaves your company, disabling their account in your identity provider automatically blocks their Tomba access.

  • Automatic user creation — With JIT (Just-In-Time) provisioning, new team members get a Tomba account the first time they sign in — no manual invitations needed.

  • Stronger security — Combine SSO with your company's existing multi-factor authentication policies.


📋 Requirements

  • A Enterprise plan. View plans.

  • You must be a workspace owner or admin to configure SSO.

  • Admin access to your identity provider (Google Workspace, Okta, Azure AD, etc.).


🚀 Getting Started

Setting up SSO takes just a few minutes. Here's the overview:

  1. Copy your Service Provider details from Tomba (Entity ID and ACS URL).

  2. Create a SAML app in your identity provider and paste the Tomba details.

  3. Upload the IdP metadata XML file back into Tomba.

  4. Test the connection by signing in with SSO.

  5. Choose your enforcement mode — let members use SSO alongside passwords, or require SSO for everyone.

  6. Verify your domain so members can discover SSO from the Tomba sign-in page.

For the full step-by-step guide, see Set Up SAML SSO.


Related Resources

Need Help?

Got questions about SSO? Contact our support team — we're here to help!

Did this answer your question?