- The Organization Admin role in StackOne.
- Admin access to the IdP, to create and configure a SAML application.
- The ability to add a DNS TXT record for your email domain, which proves you own it.
Start the connection in StackOne
1
Choose Other SAML 2.0 provider
- Go to Organization > Security > SSO.
- Click Get started.
- Select Other SAML 2.0 provider, then click Continue.
2
Name the connection and set the domain
On the Connection details step, fill in both fields, then click Continue:
- Connection name: a name for the connection. StackOne generates the connection’s unique ID from it.
- Domain: the email domain your users sign in with.
3
Copy the service provider values
The Configure your identity provider step has the values you need when you create the app in your IdP. Field names vary by IdP:
- ACS URL (Single sign-on URL): where the IdP posts the SAML assertion. Often called Assertion Consumer Service URL or Reply URL.
- SP Entity ID (Audience): identifies StackOne to the IdP. Often called Audience URI, Entity ID or Identifier.
- Default RelayState: the dashboard URL, where an IdP-initiated sign-in lands. Set it only if the IdP supports IdP-initiated sign-in.
Keep this StackOne tab open. You return to the wizard to register the provider after you build the app in your IdP.

Create the SAML app in your IdP
1
Create the SAML application
- In the IdP’s admin console, create a new SAML 2.0 application for StackOne.
- Set the following:
- Single sign-on URL (or Assertion Consumer Service URL): the ACS URL from StackOne.
- Audience URI (or Entity ID): the SP Entity ID from StackOne.
- Relay State (optional): the Default RelayState from StackOne.
2
Set the Name ID to the user's email
Set the following:
- Name ID format:
urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress. - Name ID value: the user’s work email, not a username, UPN or object ID.
email. StackOne uses it when present, and falls back to the Name ID otherwise.3
Send the user's name
Add attributes named
givenName and surname, or a single displayName. These set the user’s display name in StackOne.Adding these to an existing app only sets names for new users. To sync names for existing users, use SCIM Provisioning.
4
Sign the assertion
Enable assertion signing in the IdP. StackOne validates the signature against the certificate you register in StackOne.
5
Assign users
Assign the users or groups who should sign in to StackOne through this application, then save the app.Only assigned users can complete SSO.
6
Get the identity provider metadata
From the IdP’s SAML settings, get the values StackOne needs.
- Metadata XML
- Manual values
Download the IdP’s SAML metadata XML.
Register the provider in StackOne
Switch back to the StackOne tab and continue to the Register your SSO provider step.1
Provide the IdP values
Supply the three values from the IdP.
- Metadata XML
- Manual values
- Click Upload SAML metadata file.
- Select the metadata XML you downloaded. StackOne fills in Entity ID (Issuer), SSO URL (Entry Point), and X.509 Certificate.
- Review the imported values before continuing.
2
Register the connection
Select Continue. The connection is registered, but stays inactive until the domain is verified.
Verify the domain
Verification proves the organization owns the domain and activates SSO. Once it’s verified, existing StackOne users on the domain are linked to the SSO connection, so they keep one account.1
Copy the DNS TXT record
On the wizard’s Verify your domain step, copy the record’s Name and Value. The Value has this form:

2
Add the record to DNS
In the domain’s DNS panel, add a TXT record:
- Name/Host: the domain. Use
@if it’s the root of the DNS zone, or the subdomain label if the email domain is a subdomain. - Value: the full
_stackone-sso-verification-token-...string, as its own value. Don’t append it to an existing TXT value, such as an SPF record.
Add the record in common DNS providers
Add the record in common DNS providers
- Cloudflare
- AWS Route 53
- Google Cloud DNS
- GoDaddy
- Namecheap
- Go to DNS > Records and select Add record.
- Set Type to
TXTand Name to@for the root domain, or the subdomain label, such aseuforeu.acme.com. - Paste the token into Content.
DNS changes can take up to 48 hours to propagate, though they often complete within minutes. Check what’s publicly visible with Google Admin Toolbox Dig.
3
Verify in StackOne
- Select Verify. Once the record is visible, the domain is verified and SSO is active.
- Select Finish to close the wizard.
To finish setup first, select Verify Later, then verify afterward from the Trusted Domain card on the connection’s General tab.

Manage the connection
Open the connection from Organization > Security > SSO. The General tab is where you maintain it after setup:- Select Edit SAML to update the identity provider values, either by uploading new metadata XML or by editing the Entity ID (Issuer), SSO URL (Entry Point), and X.509 Certificate directly.
- Select Edit Domain to change the trusted domain. Changing it resets verification, so users stop being redirected until you verify it again. You can’t change it while SSO is enforced.

- Settings edits the Connection name. The Provider ID is generated at setup and can’t be changed.
- Delete removes the SSO connection. It’s disabled while SSO is enforced, so turn off enforcement on the Authentication tab first.
Troubleshooting
Next steps
Single Sign-On
How SSO, SCIM Provisioning, and domain verification fit together.
Okta SSO
The same setup with Okta’s field names and screenshots.
Microsoft Entra SSO
The same setup with Microsoft Entra ID.
