Prerequisites
- An organization Owner or Admin role and SAML SSO enabled through your plan capabilities.
- Administrative access to your identity provider (IdP).
- A verified organization domain if you want to link a domain. Domains are optional when using the dedicated sign-in URL.
Step 1: Get Krea’s Service Provider Details
Open Domains & Access ↗. In SAML SSO Configurations, click New Configuration and give the connection a recognizable name. Copy the service-provider values shown in the panel for your IdP:Step 2: Configure Your Identity Provider
Create a SAML application in your identity provider using the values from Step 1.- Okta
- Google Workspace
1
Access Applications
Log in to your Okta Admin Console (typically
https://your-org.okta.com/admin) and go to Applications → Applications in the sidebar.2
Create App Integration
Click Create App Integration.Select SAML 2.0 as the sign-in method and click Next.
3
Configure General Settings
Enter Krea as the App name.Optionally upload a logo for easy identification.Click Next.
4
Configure SAML Settings
Enter the following values:
5
Complete Setup
Click Next.On the Feedback page, select “I’m an Okta customer adding an internal app” and click Finish.
6
Get Metadata URL
On the application page, go to the Sign On tab.Scroll down to SAML Signing Certificates and find the Metadata URL. Click Actions → View IdP metadata to get the URL.
7
Assign Users
Go to the Assignments tab and assign the users or groups who should have access to Krea.
Reference: Okta Help - Create SAML App Integrations ↗
Step 3: Connect Your IdP to Krea
In the new configuration panel, choose Metadata URL or Metadata XML and provide the metadata from your IdP.- Metadata URL: Supply the IdP’s publicly accessible SAML metadata URL.
- Metadata XML: Paste the metadata XML downloaded from your IdP. Use this when a public metadata URL is unavailable.
Step 4: Test Your Configuration
1
Copy the sign-in URL
Copy SSO Sign-in URL from the active configuration’s row in SAML SSO
Configurations.
2
Open a private browser window
Open that URL in a fresh private window and authenticate with a user
assigned to the Krea application in your IdP.
3
Check workspace access
Confirm the user reaches Krea and can access the intended workspace.
Configure Workspace Access on the organization’s Workspaces page
when needed.
Enforce SAML SSO
After testing an active configuration:1
Manage the configuration
In Domains & Access → SAML SSO Configurations, click Manage for the
connection.
2
Require SSO for the domain
Under Domains (optional), set the verified domain to SSO required.
3
Save the policy
Click Save name & domain settings.
Workspace Access After SSO
Open Workspaces → Workspace Access. You can configure organization-wide access and additional access for each named SAML connection:- Inherit uses the organization-wide setting.
- Joinable lets eligible users discover and join a workspace.
- Auto-join adds users to that workspace after signing in through the connection.
Updating IdP Metadata
Click Manage on the configuration:- For a URL-based configuration, use Refresh from URL. If you edit the URL, click Update URL & refresh to apply it.
- For XML, choose Replace metadata XML, paste the replacement, and click Replace metadata. Stored XML is not displayed.
An existing configuration cannot switch between URL and XML formats. Changing
formats requires replacing the configuration. Coordinate the new sign-in URL,
domain links, and workspace access before removing the old setup.
Deleting a Configuration
Open Manage, click Delete Configuration, then Confirm Delete. Deletion removes that configuration’s domain links and connection-specific onboarding access mappings. Coordinate an alternative sign-in method with affected users before deleting it.Troubleshooting
Provisioning failed
Provisioning failed
Review the error shown beside the configuration. Check the ACS URL and
Entity ID, verify that the metadata URL is accessible or that the XML is
valid, and check the IdP’s signing certificate.
Users can't sign in
Users can't sign in
Confirm the configuration is active and the user is assigned to the IdP
application. For email-based SSO, check that their domain is verified and
linked to the intended configuration. For a connection without domains, use
its dedicated sign-in URL.
Sign-in works but the user can't access a workspace
Sign-in works but the user can't access a workspace
Review Workspace Access for the organization and the user’s SAML
connection, or add the user directly to the workspace. Authentication and
workspace membership are separate.
I can't select a domain
I can't select a domain
Pending domains must be verified first. A domain marked as used by another
configuration must be unlinked there before it can be linked here.