Skip to main content
Krea organizations can configure named SAML connections for their identity providers. Each active configuration has its own SSO Sign-in URL. You can also link verified domains to make SSO optional or required for those domains.

Prerequisites

  • An organization Owner or Admin role and SAML SSO enabled through your plan capabilities.
  • Administrative access to your identity provider (IdP).
  • A verified organization domain if you want to link a domain. Domains are optional when using the dedicated sign-in URL.
If configuration controls are unavailable, contact Krea support.

Step 1: Get Krea’s Service Provider Details

Open Domains & Access ↗. In SAML SSO Configurations, click New Configuration and give the connection a recognizable name. Copy the service-provider values shown in the panel for your IdP:

Step 2: Configure Your Identity Provider

Create a SAML application in your identity provider using the values from Step 1.
1

Access Applications

Log in to your Okta Admin Console (typically https://your-org.okta.com/admin) and go to Applications → Applications in the sidebar.
2

Create App Integration

Click Create App Integration.Select SAML 2.0 as the sign-in method and click Next.
3

Configure General Settings

Enter Krea as the App name.Optionally upload a logo for easy identification.Click Next.
4

Configure SAML Settings

Enter the following values:
5

Complete Setup

Click Next.On the Feedback page, select “I’m an Okta customer adding an internal app” and click Finish.
6

Get Metadata URL

On the application page, go to the Sign On tab.Scroll down to SAML Signing Certificates and find the Metadata URL. Click Actions → View IdP metadata to get the URL.
7

Assign Users

Go to the Assignments tab and assign the users or groups who should have access to Krea.

Step 3: Connect Your IdP to Krea

In the new configuration panel, choose Metadata URL or Metadata XML and provide the metadata from your IdP.
  • Metadata URL: Supply the IdP’s publicly accessible SAML metadata URL.
  • Metadata XML: Paste the metadata XML downloaded from your IdP. Use this when a public metadata URL is unavailable.
Under Domains (optional), you can link a verified domain with SSO optional, or leave domains unlinked and use the dedicated sign-in URL. A domain already linked to another configuration is shown as in use. Click Create Configuration. Wait for provisioning to complete before testing. A Failed status includes an error to help diagnose setup.

Step 4: Test Your Configuration

1

Copy the sign-in URL

Copy SSO Sign-in URL from the active configuration’s row in SAML SSO Configurations.
2

Open a private browser window

Open that URL in a fresh private window and authenticate with a user assigned to the Krea application in your IdP.
3

Check workspace access

Confirm the user reaches Krea and can access the intended workspace. Configure Workspace Access on the organization’s Workspaces page when needed.
Users with a linked domain can also choose SSO on Krea’s login page ↗ and enter their email. For a configuration without domains, share its dedicated sign-in URL.

Enforce SAML SSO

After testing an active configuration:
1

Manage the configuration

In Domains & Access → SAML SSO Configurations, click Manage for the connection.
2

Require SSO for the domain

Under Domains (optional), set the verified domain to SSO required.
3

Save the policy

Click Save name & domain settings.
Required SSO restricts authentication for users on the linked domain. Make sure those users are assigned to the IdP application and can complete SSO before enabling it. Do not rely on an existing non-SSO session continuing indefinitely after enforcement changes.
To stop requiring SSO while keeping it available, change the domain to SSO optional and save. No SSO removes the domain link from that configuration. Domain capture is separate: its Off, Optional, and Enforced choices control enrollment, not whether SSO is required.

Workspace Access After SSO

Open Workspaces → Workspace Access. You can configure organization-wide access and additional access for each named SAML connection:
  • Inherit uses the organization-wide setting.
  • Joinable lets eligible users discover and join a workspace.
  • Auto-join adds users to that workspace after signing in through the connection.
Organization-wide access also applies. A connection-specific setting cannot take away access already granted organization-wide. See Managing Your Organization.

Updating IdP Metadata

Click Manage on the configuration:
  • For a URL-based configuration, use Refresh from URL. If you edit the URL, click Update URL & refresh to apply it.
  • For XML, choose Replace metadata XML, paste the replacement, and click Replace metadata. Stored XML is not displayed.
Saving the name and domain settings does not apply metadata changes. Refresh or replace metadata explicitly, including when your IdP rotates its signing certificate.
An existing configuration cannot switch between URL and XML formats. Changing formats requires replacing the configuration. Coordinate the new sign-in URL, domain links, and workspace access before removing the old setup.

Deleting a Configuration

Open Manage, click Delete Configuration, then Confirm Delete. Deletion removes that configuration’s domain links and connection-specific onboarding access mappings. Coordinate an alternative sign-in method with affected users before deleting it.

Troubleshooting

Review the error shown beside the configuration. Check the ACS URL and Entity ID, verify that the metadata URL is accessible or that the XML is valid, and check the IdP’s signing certificate.
Confirm the configuration is active and the user is assigned to the IdP application. For email-based SSO, check that their domain is verified and linked to the intended configuration. For a connection without domains, use its dedicated sign-in URL.
Review Workspace Access for the organization and the user’s SAML connection, or add the user directly to the workspace. Authentication and workspace membership are separate.
Pending domains must be verified first. A domain marked as used by another configuration must be unlinked there before it can be linked here.
For help with your configuration, contact support@krea.ai.