Skip to main content

Enterprise SSO

Enterprise SSO lets employees log in to Revizo with the organisation’s own identity provider, for example Microsoft Entra, Okta, or Google Workspace.

Before you start​

You must be an organisation administrator in Revizo. You also need help from an IT administrator who can create a SAML or OIDC application at the identity provider.

The roles in the setup are typically:

RoleDoes this
Revizo administratorStarts the SSO setup, verifies the domain, and enables the connection in Revizo
IT administratorCreates the SSO application at Microsoft Entra, Okta, or Google Workspace
RevizoChecks the domain and connects the organisation to Clerk Enterprise SSO

If you do not have access to DNS or the identity provider, you can still start the setup and use Send this to IT in Revizo.

1. Verify the domain​

In Revizo go to Settings → SSO and enter the company domain. Revizo shows a DNS TXT record.

Add the TXT record at the domain provider:

  • Type: TXT
  • Name: the value Revizo shows, for example _revizo-sso
  • Value: the value Revizo shows, for example revizo-sso=...

When the DNS record is saved, click Verify DNS in Revizo.

tip

DNS can take a few minutes to update. If verification fails right after the record is added, wait a bit and try again.

2. Send the setup to IT​

When the domain is verified, choose identity provider in Revizo and use the Open email or Copy button in the “Send this to IT” box.

IT creates the SSO application and usually sends you one of these values:

  • SAML metadata URL (recommended)
  • SAML metadata XML
  • OIDC discovery URL, client ID, and client secret

We recommend SAML metadata URL when possible. Then you do not have to copy certificate, Entity ID, and SSO URL manually.

What do the fields in Revizo mean?​

FieldWhat it meansWhere to find it
Metadata URLA URL that describes the SAML setup at the identity providerMicrosoft Entra: SAML Certificates → App Federation Metadata Url. Okta: Sign On → Metadata URL
Metadata XMLThe same information as the metadata URL, but as a file/textDownloaded from the identity provider
Entity IDIdentifier for the IdP applicationOften called Entity ID or Issuer
SSO URLThe URL the user is sent to for loginOften called Login URL or Single Sign-On URL
X.509 certificateThe certificate Revizo/Clerk uses to trust the IdP signatureLocated in the SAML certificate section
Discovery URLOIDC metadata endpointMicrosoft Entra uses tenant ID in the URL
Client IDThe ID of the OIDC applicationMicrosoft Entra: Application (client) ID
Client secretSecret value for the OIDC applicationMicrosoft Entra: Certificates & secrets → Value

Where does IT find the values?​

Microsoft Entra​

For SAML:

  1. Go to Microsoft Entra admin center.
  2. Open Enterprise applications.
  3. Select the Revizo application.
  4. Go to Single sign-on → SAML.
  5. Find App Federation Metadata Url under SAML Certificates.

For OIDC:

  1. Go to App registrations.
  2. Open the app for Revizo.
  3. Application (client) ID is the client ID.
  4. Directory (tenant) ID is used in the discovery URL:
https://login.microsoftonline.com/<tenant-id>/v2.0/.well-known/openid-configuration

The client secret is created under Certificates & secrets. Use Value, not Secret ID.

Okta​

For SAML:

  1. Go to Applications in Okta.
  2. Open the Revizo application.
  3. Go to Sign On.
  4. Copy Metadata URL or download the metadata XML.

Google Workspace​

For SAML:

  1. Go to Google Admin Console.
  2. Open Apps → Web and mobile apps.
  3. Open the Revizo application.
  4. Download the metadata XML or copy the metadata link if it is shown.

3. Enable SSO​

Paste the metadata URL or metadata XML in Revizo and click Enable SSO.

If you use OIDC, open Advanced setup and fill in discovery URL, client ID, and client secret.

After enabling, you should test with one user from the domain before you ask all employees to use SSO.

Troubleshooting​

DNS verification fails​

Check that the TXT record is published on the correct name and that the value is copied exactly. The name should usually be _revizo-sso, not the full domain, if the domain provider already appends the domain automatically.

SSO enablement fails​

Check that the metadata URL is publicly available and that the domain in the identity provider matches the company domain in Revizo.

Microsoft Entra: which secret should be used?​

Use Value from the client secret, not Secret ID. Secret ID looks correct, but does not work as a client secret.

The user does not enter the correct Revizo organisation​

Contact Revizo support. The SSO connection must be tied to the correct organisation in Clerk.