Enterprise SSO
Enterprise SSO lets employees log in to Revizo with the organisation’s own identity provider, for example Microsoft Entra, Okta, or Google Workspace.
Before you start
You must be an organisation administrator in Revizo. You also need help from an IT administrator who can create a SAML or OIDC application at the identity provider.
The roles in the setup are typically:
| Role | Does this |
|---|---|
| Revizo administrator | Starts the SSO setup, verifies the domain, and enables the connection in Revizo |
| IT administrator | Creates the SSO application at Microsoft Entra, Okta, or Google Workspace |
| Revizo | Checks the domain and connects the organisation to Clerk Enterprise SSO |
If you do not have access to DNS or the identity provider, you can still start the setup and use Send this to IT in Revizo.
1. Verify the domain
In Revizo go to Settings → SSO and enter the company domain. Revizo shows a DNS TXT record.
Add the TXT record at the domain provider:
- Type: TXT
- Name: the value Revizo shows, for example
_revizo-sso - Value: the value Revizo shows, for example
revizo-sso=...
When the DNS record is saved, click Verify DNS in Revizo.
DNS can take a few minutes to update. If verification fails right after the record is added, wait a bit and try again.
2. Send the setup to IT
When the domain is verified, choose identity provider in Revizo and use the Open email or Copy button in the “Send this to IT” box.
IT creates the SSO application and usually sends you one of these values:
- SAML metadata URL (recommended)
- SAML metadata XML
- OIDC discovery URL, client ID, and client secret
We recommend SAML metadata URL when possible. Then you do not have to copy certificate, Entity ID, and SSO URL manually.
What do the fields in Revizo mean?
| Field | What it means | Where to find it |
|---|---|---|
| Metadata URL | A URL that describes the SAML setup at the identity provider | Microsoft Entra: SAML Certificates → App Federation Metadata Url. Okta: Sign On → Metadata URL |
| Metadata XML | The same information as the metadata URL, but as a file/text | Downloaded from the identity provider |
| Entity ID | Identifier for the IdP application | Often called Entity ID or Issuer |
| SSO URL | The URL the user is sent to for login | Often called Login URL or Single Sign-On URL |
| X.509 certificate | The certificate Revizo/Clerk uses to trust the IdP signature | Located in the SAML certificate section |
| Discovery URL | OIDC metadata endpoint | Microsoft Entra uses tenant ID in the URL |
| Client ID | The ID of the OIDC application | Microsoft Entra: Application (client) ID |
| Client secret | Secret value for the OIDC application | Microsoft Entra: Certificates & secrets → Value |
Where does IT find the values?
Microsoft Entra
For SAML:
- Go to Microsoft Entra admin center.
- Open Enterprise applications.
- Select the Revizo application.
- Go to Single sign-on → SAML.
- Find App Federation Metadata Url under SAML Certificates.
For OIDC:
- Go to App registrations.
- Open the app for Revizo.
- Application (client) ID is the client ID.
- Directory (tenant) ID is used in the discovery URL:
https://login.microsoftonline.com/<tenant-id>/v2.0/.well-known/openid-configuration
The client secret is created under Certificates & secrets. Use Value, not Secret ID.
Okta
For SAML:
- Go to Applications in Okta.
- Open the Revizo application.
- Go to Sign On.
- Copy Metadata URL or download the metadata XML.
Google Workspace
For SAML:
- Go to Google Admin Console.
- Open Apps → Web and mobile apps.
- Open the Revizo application.
- Download the metadata XML or copy the metadata link if it is shown.
3. Enable SSO
Paste the metadata URL or metadata XML in Revizo and click Enable SSO.
If you use OIDC, open Advanced setup and fill in discovery URL, client ID, and client secret.
After enabling, you should test with one user from the domain before you ask all employees to use SSO.
Troubleshooting
DNS verification fails
Check that the TXT record is published on the correct name and that the value is copied
exactly. The name should usually be _revizo-sso, not the full domain, if
the domain provider already appends the domain automatically.
SSO enablement fails
Check that the metadata URL is publicly available and that the domain in the identity provider matches the company domain in Revizo.
Microsoft Entra: which secret should be used?
Use Value from the client secret, not Secret ID. Secret ID looks correct, but does not work as a client secret.
The user does not enter the correct Revizo organisation
Contact Revizo support. The SSO connection must be tied to the correct organisation in Clerk.