Scanverra
Enterprise SSO / SAML

Guides

Enterprise SSO / SAML

Scanverra supports SAML 2.0 single sign-on on the Enterprise plan, so your team signs in with your existing identity provider instead of individual Google or GitHub accounts.

SSO setup is handled directly with your account manager, not self-service — this page exists so your IT/security team knows what to expect and what to prepare ahead of time.

How it works

  1. 1A user goes to the Scanverra sign-in page and chooses Continue with SSO, entering their work email.
  2. 2Scanverra recognizes the email domain and redirects them to your identity provider to authenticate.
  3. 3After authenticating, your IdP redirects back to Scanverra with a signed SAML response, and the user is signed in.

What we need from your identity provider

Any SAML 2.0 IdP works — Okta, Microsoft Entra ID (Azure AD), OneLogin, Google Workspace, and others.

Send us

  • The email domain your team signs in with (e.g. acme.com)
  • Your IdP's SSO URL (also called Login URL, SSO endpoint, or entryPoint)
  • Your IdP's signing certificate (X.509, PEM format)

Our SP metadata

What to configure on your side when setting up the Scanverra application in your IdP.

SP Entity ID / Audiencehttps://scanverra.com
ACS URL / Reply URLhttps://www.scanverra.com/api/auth/saml/callback
BindingHTTP-POST
NameID formatEmail address (recommended)
Signed responses required:your IdP must sign both the SAML response and the assertion. This is the default behavior for every major IdP, so it typically requires no extra configuration on your end — we mention it because we don't accept unsigned responses, for security reasons.

Ready to set up SSO?

SSO is available on the Enterprise plan. Reach out to your account manager or contact support with the details above and we'll get it configured.

Contact support