Skip to main content

Set up SAML Single Sign-On (SSO)

Set up, configure, and manage SAML SSO for your Culture Amp account. Covers guidance for self-service configuration, testing, troubleshooting, and certificate management.

Written by Sterling Rayment

Who can use this feature?

Available on:

  • All Culture Amp subscriptions

Customers with existing legacy SSO integrations: Configuring SSO through the self-service flow will automatically disable your legacy connection.

Single Sign-On (SSO) lets your team securely access Culture Amp using your organization's existing identity provider (IdP), such as Okta or Microsoft Azure AD. Once configured, your employees sign in using the same credentials they use for other work applications, with no separate password required.

This article covers how to set up, configure, and manage SSO for your Culture Amp account.

Before You Start


To set up SSO, you'll need:

Note: SSO setup typically takes 15–30 minutes to complete.

Important: Pre-built standard application connectors (such as those in the Okta or Azure AD app galleries) are not supported for the self-service SSO setup. You will need to manually configure a custom SAML application within your identity provider using the values provided in this article. This is because Culture Amp uses SP-initiated SAML — sign-in must begin from a Culture Amp link, not from a native app tile in your IdP. Attempting to sign in via a default tile (for example, the Culture Amp tile in the Okta or Google Workspace gallery) will result in a missing_redirect_uri error.

For a one-click alternative, see Simulate an IdP-Initiated Flow.

IdP-specific configuration guides

To assist with the configuration, we have created step-by-step guides for some common identity providers. If your IdP is listed below, we recommend following the relevant guide alongside the general setup steps above.

Setting up SSO


The following steps can be used to set up SSO for the account, without needing to send any details to Culture Amp support.

Step 1: Access Authentication settings

  1. Go to Settings > Account > Authentication.

  2. Click +Add SAML Provider.

Note: If you've previously started but not completed a self-service SSO setup, clicking +Add SAML Provider will return you to your existing draft rather than creating a new one. Only one draft configuration can exist at a time.

Step 2: Add Culture Amp to your identity provider

Culture Amp displays two values in the setup wizard. Copy each one exactly into your IdP:

SAML Callback/Assertion Consumer Service (ACS) URL:

Copy this URL exactly and paste it into your IdP.

SAML Audience / Entity ID:

Copy this value exactly and paste it into your IdP.

Tip: Make sure your users are assigned to the Culture Amp application in your IdP. Users not assigned to your IdP won't be able to log in via SSO.

Step 3: Enter your identity provider details

Refer to your identity provider's settings to find the following details. Each value must be copied and pasted manually into Culture Amp:

Note: Culture Amp does not currently support importing configuration from a metadata URL or XML file. All fields must be entered manually by copying from your identity provider.

  1. Enter your SAML endpoint URL: The sign-in URL from your identity provider. Must start with https://

  2. Enter your SAML cert: Your identity provider’s X.509 signing certificate. Copy it exactly as shown in your IdP.

  3. Select your Nameid-format: choose Email Address if your IdP sends the user’s email address (recommended for most setups), or Unspecified if your IdP sends a different identifier, such as employee ID.

Note: Your certificate should be accepted whether or not it includes the -----BEGIN CERTIFICATE----- and -----END CERTIFICATE----- lines. Any leading spaces or linebreaks should also be automatically trimmed by the setup wizard.

Step 4: Set a friendly name

In the Identity provider friendly name field, enter a display name for your SSO provider. This is a required field.

  • Enter a custom name for your SSO provider (e.g., Hooli SSO).

  • This name appears on the login button as Sign in with [Hooli SSO].

  • A live preview is shown as you type, so you can see exactly how the button will appear to your users.

  • Click Next to proceed to the Verify screen.

Step 5: Verify your SSO connection

On the Verify screen, you’ll see a test sign-in link. Follow these steps:

  1. Click the copy button next to the Sign in page link, and paste it into a private or incognito browser window.

  2. Log in using your IdP credentials.

  3. If successful, return to the wizard and tick the checkbox: “I was able to sign in successfully using SSO”.

  4. Click Finish to complete setup and enable SSO.

  5. If the test fails, click Back to return to the configuration screen and review your settings. See Troubleshooting below for help.

Password login during setup

If your account is currently SSO-only, with no password or Google login already enabled, temporary password login will be automatically enabled as a lockout safeguard.

On the Verify screen, you’ll see a “Deactivate temporary password login after 24 hours” checkbox, which is ticked by default. Untick it to keep password login active longer, or disable it sooner from Settings > Account > Authentication. If password or Google login is already enabled on your account, this safeguard does not apply.

Step 6: Setup complete

After clicking Finish, a confirmation screen appears: SSO is now enabled. Users can now log in to Culture Amp using SSO. Click Return to settings to go back to your Authentication settings.

Important: If you had an existing legacy SSO connection, it is automatically disabled when your new connection is activated. Only your new, personalised login button will appear on the sign-in page.

Simulate an IdP-initiated flow


Culture Amp uses SP-initiated SAML, which means sign-in must start from a Culture Amp link, not from a standard app tile in your identity provider. To give your team a convenient one-click login experience, you can create a custom bookmark or tile in your IdP pointing directly to your account's SAML login URL.

This URL will be found on your Verify page when moving through the setup steps, and will be unique to your SAML integration. This means you can copy the link from that page directly without any need to edit it.

We have linked some useful guides for some common IdP's below, to help with the process:

Managing your SAML/SSO


Editing your configuration

  1. Go to Settings > Account > Authentication.

  2. Click Edit configuration.

  3. Update the required fields.

  4. Click Next.

  5. Test the connection to confirm it's still working correctly.

Important: Changes to an active SSO configuration take effect immediately. Incorrect settings could prevent users from logging in. We recommend testing any changes outside of peak hours.

Updating your certificate

If your IdP certificate expires or is rotated, SSO will stop working for all users. Before updating your certificate, check which type of SSO connection you have:

  • Self-service connection: You can update your certificate directly by editing your existing configuration (see steps below).

  • Legacy connection (support-assisted): You cannot update the certificate by editing the existing configuration.

If you have a self-service connection, update your certificate via the following steps without disrupting access:

  1. Go to Settings > Account > Authentication.

  2. Click Edit configuration.

  3. Paste your new certificate into the Certificate field.

  4. Click Next and test the connection to confirm everything is working.

  5. If successful, tick the checkbox: I was able to sign in successfully using SSO.

  6. Click Finish to finalize the changes.


If you have a legacy connection, you cannot renew the certificate by editing the existing configuration. Instead, complete the full self-service SSO setup using the steps in this article. During setup, you can enter your updated certificate along with the other required details. Once your new connection is activated, your legacy connection will automatically be disabled.

We recommend migrating to the self-service flow rather than asking support to manually update the certificate for the legacy connection on the back-end. Legacy connections will not be supported indefinitely, so migrating now means you won't face this issue again in future.

Tip: Update your certificate before it expires to avoid disrupting your users' access.

Deleting or deactivating your SAML connection

If required, you can delete or temporarily deactivate your SAML connection at any time.

  1. Go to Settings > Account > Authentication.

  2. Click Delete, and then Delete again to confirm you would like to proceed.

    • If you only need to deactivate the SAML option temporarily, click the green toggle instead. Once it is grey, it is deactivated.

Note: You will not be able to deactivate or delete your SAML connection if it is the only authentication option enabled for your account. Make sure Password, Google or another SAML connection is enabled before attempting to delete or deactivate it.

Managing authentication options

If you would like to disable the Password or Google sign-in options after you have successfully configured SAML:

  1. Go to Settings > Account > Authentication.

  2. Click the green toggle next to the authentication options you want to disable.

You can manage these options at any time, but always need at least one authentication option enabled.

Troubleshooting


Users cannot log in via SSO

Work through the following checks:

  1. Check SSO is enabled

    Go to Settings > Account > Authentication and confirm that your SSO connection is appearing with the toggle showing 'enabled.'

  2. Check that the user is assigned in your IdP

    In your IdP admin panel, confirm the affected user is assigned to the Culture Amp application.

  3. Check that the user exists in Culture Amp

    Go to Settings > Users and search for the affected user. If they don't exist, add them first.

  4. Check the user’s email address matches

    Confirm the user’s email address is identical in both Culture Amp and your IdP.

  5. Check your IdP certificate hasn't expired

    If your certificate has expired, renew it in your IdP and update it in Culture Amp. Updating your certificate above.

SSO configuration test fails

Check the following in your IdP configuration:

  • The ACS URL in your IdP exactly matches the URL shown in Culture Amp's authentication settings.

  • The Entity ID in your IdP exactly matches the value shown in Culture Amp's authentication settings.

  • The certificate is complete, in X.509 PEM format.

  • The SAML endpoint URL starts with https:// or http://.

  • The Nameid-format in Culture Amp matches what your IdP is configured to send.

  • Ensure you have created a custom SAML integration in your IdP rather than using a standard connector (selecting the Culture Amp app through the app gallery) as standard connectors are not supported for the new flow.

My SSO configuration won't save

Check to make sure the following is true:

  • Your SAML endpoint URL starts with https:// or http://.

  • Your certificate is in X.509 format.

  • You’ve selected a Nameid-format. Only Email and Unspecified are supported.

  • You’ve entered an Identity provider friendly name — this field is required.

  • You have the Account Admin or Account Configuration role in Culture Amp.

I'm seeing a missing_redirect_uri error

This error occurs when sign-in is initiated from a standard app tile or launcher in your identity provider. Culture Amp uses SP-initiated SAML, which requires sign-in to begin from a Culture Amp link.

To resolve this, replace any standard IdP connector tile with a custom bookmark or tile pointing to your account's login URL found on the Verify page during setup.

Note: This link will be unique to your SAML integration, so be sure to copy it directly from the Verify page. See Simulate an IdP-Initiated Flow above for more information, including IdP-specific guides.

FAQs


My legacy connection SSO certificate has expired. What should I do?

If your SSO was originally configured by the Culture Amp support team (a legacy integration), you cannot renew the certificate by editing the existing configuration. The legacy support-assisted setup is no longer supported. Instead, you'll need to migrate to a new self-service SSO connection using the steps in this article. The setup typically takes 15–30 minutes.

Before you begin, take note of two important limitations of the self-service flow:

  • Standard IdP app connectors are not supported. Do not use the pre-built Culture Amp connector from your IdP's app gallery (such as the Okta or Azure AD gallery tile). You must create a custom SAML application in your IdP and manually enter the values provided in the Culture Amp setup wizard.

  • Sign-in must start from a Culture Amp link — standard IdP app tiles will not work. Culture Amp uses SP-initiated SAML. If your team currently launches Culture Amp from an app tile in your IdP, attempting to sign in this way will result in a missing_redirect_uri error. You'll need to replace the tile with a custom bookmark pointing to your Culture Amp login URL. See Simulate an IdP-initiated flow for instructions.

Can users still log in with a native password after SSO is activated?

Yes. By default, users can log in using any enabled authentication method. SSO, password, or Google OAuth. You can disable other login methods via your authentication settings to enforce SSO-only login, but we generally recommend keeping password enabled as a safeguard.

Do all users have to use SSO?

No. Users can choose which login method to use, provided that method is enabled. However, if a user is not assigned to Culture Amp in your IdP, they cannot use SSO and will need to use another method.

What happens if SSO stops working?

If password login is still enabled, users can log in using that method while the SSO issue is resolved. Account Admins and Account Configuration users can also re-enable password sign-in themselves via Settings → Account → Authentication.

If SSO is the only enabled login method and admins are fully locked out, contact Culture Amp Support — they can re-enable password authentication on your behalf. An admin will need to initiate that request directly.

Can I import my configuration from a metadata URL?

No. The self-service SAML wizard does not support importing from a metadata URL or uploading a metadata XML file. You must manually copy and paste each of the following from your identity provider:

  • SAML endpoint URL

  • SAML cert (X.509 signing certificate)

  • Nameid-format

If your IdP offers a metadata URL, you can use it as a reference to find the correct values; you’ll just need to copy each field individually. If you need help with a more complex setup, contact Culture Amp support.

What SAML version does Culture Amp support?

Culture Amp supports SAML 2.0. SAML 1.1 is not supported.

Does Culture Amp automatically create accounts for users who log in via SSO?

No. Users must already exist in Culture Amp before they can log in via SSO. There is no automatic account creation (sometimes called Just-In-Time or JIT provisioning).

Can I test SSO without affecting my users?

As soon as you click Next on the first step of your configuration, your SSO connection should be active (provided all details have been entered accurately). This means once you are on the Verify page, where you can test before finalizing, there is a chance users will be able to access the SSO login flow.

If your testing shows errors and you're unable to fix these by editing the configuration, feel free to start a support conversation and 'ask a person' to be connected with the support team. They help to reset the flow to ensure users are not seeing the option to log in via SSO while the issues are looked into.

Can I use employee ID instead of email address to authenticate?

Yes. If your identity provider (IdP) uses employee ID as the identifier rather than email address, select Unspecified as the Nameid-format in Step 3 of the SSO setup wizard.

You'll also need to configure your IdP to send the employee ID as the SAML Name ID with the name ID format set to Unspecified. The exact steps depend on your IdP, but the general approach is:

The employee ID value in your directory must match the employee ID stored against the user's account in Culture Amp. If you need help configuring this for your specific IdP, contact Culture Amp support.

Can I configure more than one SSO integration?

By default, only one SSO connection can be configured in your Authentication settings. Once you have set up your initial integration, you will notice that the +Add SAML Provider button is removed.

If you do require multiple connections attached to the same Culture Amp account, "Ask a Person" in a support conversation to connect with a support specialist who can enable a feature flag on your account, allowing an additional integration. Please note that this may be a paid add-on in future.

Do participants need to log in with SSO to submit their survey?

By default, participants do not need to sign into their accounts to access a survey. They can access their unique survey link via their survey invitation without the need to authenticate via SSO.

However, if you would prefer authentication to be a requirement for participants to access the survey, authenticated capture can be enabled. Just "Ask a Person" in a support conversation, and the team can help to get that set up.


💬 Need help? Open a support conversation to speak with our Product Support team.

Did this answer your question?