Skip to main content

Single sign-on (SSO)

How to set up SAML/OIDC single sign-on and SCIM directory sync so your team signs in and is provisioned through your identity provider.

C
Written by Cameron Soregaroli

This article explains how to set up single sign-on (SSO) for your organization and how directory sync keeps user access current.

How do I set up SSO for my organization?

PerkUp supports SAML and OIDC single sign-on, configured through a self-serve admin portal. Your company's IT admin completes the identity provider (IdP) configuration themselves — PerkUp works with Okta, Azure AD, Google, and other standard SAML/OIDC providers. You need admin access to start this setup.

Will my team sign in through our identity provider once SSO is set up?

Yes. Once SSO is configured, members of your organization sign in through your identity provider instead of using PerkUp's standard Google sign-in or email magic link. The signed-in email still resolves to that person's record in PerkUp, so rewards continue to be keyed to the correct person.

Can SSO automatically add or remove users?

Yes, if you enable directory sync (SCIM). SCIM can provision new users and deprovision users directly from your identity provider, so access changes made in your IdP carry over to PerkUp without a manual step in PerkUp itself.

How long does it take for a deprovisioned user to lose access?

Directory sync latency runs up to 24 hours. If you deprovision someone in your identity provider, expect their PerkUp access to be removed within that window rather than instantly — this is expected behavior, not a sign that sync failed. Deprovisioned users are removed from PerkUp once the sync runs.

Do I still need to configure users manually in PerkUp?

If you're using SCIM directory sync, no — provisioning and deprovisioning happen through your IdP. If you're using SSO for authentication only, without directory sync, you'll continue to add and remove people in PerkUp directly or through your HRIS connection. See "Syncing your team from your HRIS" if you'd rather manage your roster from an HRIS instead of an IdP.

For general sign-in troubleshooting outside of SSO, see "Why can't I sign in?" and "I can't log in to PerkUp".

  • Some SSO integrations carry an additional fee — check your PerkUp contract or ask your CSM before rolling out.

  • If sign-in still fails after these steps, record the full login attempt (a short screen recording helps enormously) and send it to support so we can trace exactly where it breaks.

Did this answer your question?