---
title: Single sign-on (SSO)
description: Learn how to setup the Single sign-on (SSO) authentication method on the Parashift platform
---

[Skip to content](https://support.parashift.io/single-sign-on-sso#main-content)

[Contact us](https://support.parashift.io/kb-tickets/new?hsLang=en) [Customer support portal](https://support.parashift.io/tickets-view?hsLang=en)

[![parashift\_logo\_white-2](https://support.parashift.io/hs-fs/hubfs/parashift_logo_white-2.png?width=250&height=45&name=parashift_logo_white-2.png)](https://support.parashift.io/?hsLang=en)

Open main navigation

Close main navigation

- [Contact us](https://support.parashift.io/kb-tickets/new)
- [Customer support portal](https://support.parashift.io/tickets-view)

 How can we help you?

- There are no suggestions because the search field is empty.

1. [Support Center](https://support.parashift.io/?hsLang=en)
2. [User Guides](https://support.parashift.io/user-guides?hsLang=en)
3. [General](https://support.parashift.io/user-guides?hsLang=en#general)

# Single sign-on (SSO)

## Learn how to use the Single sign-on (SSO) authentication method on the Parashift platform

This article explains how to set up **Single Sign-On (SSO)** for your Parashift tenant.   
Since SSO configuration cannot be done directly in the Parashift web interface, the setup is completed in cooperation with [Parashift Support](mailto:support@parashift.io).

You can choose between:

- Using the **Parashift Platform** OpenID Connect (OIDC) multi-tenant **Azure application** (simplest option), or
- Using **your own OpenID Connect (OIDC) or SAML provider**

---

### Option 1: Use the Parashift Platform app (Recommended)

This is the simplest and fastest way to enable SSO if you are using Microsoft Entra ID (Azure AD).

**How it works**

- Parashift Support links your (parent) tenant to the built-in Microsoft Graph SSO provider.
- Users sign in using the **“Sign in with Microsoft”** button.
- Your Microsoft admin approves the Parashift Platform app once, during the first login attempt.

**Steps**

1. **Contact Parashift Support**  
   Ask them to associate your (parent) tenant with the `microsoft_graph` SSO IDP.
2. **Admin approval (client side)**
   
     - When the first user attempts to log in, Microsoft will automatically create an app approval request.
     - A Microsoft tenant admin must approve the Parashift Platform app.
3. **User login**
   
     - After approval, users can log in using Sign in with Microsoft.

**Why Recommended?**

✅ No client secret management required  
✅ Minimal setup effort  
✅ Recommended for Microsoft-based environments

---

### Option 2: Use your own OpenID Connect (OIDC) provider

If you prefer to use your own identity provider (e.g. Auth0, Okta, custom Azure AD app), Parashift can configure a dedicated SSO integration for you.

**Step 1: Contact Parashift Support**

SSO cannot be configured via the web interface. Contact Parashift Support and provide:

- Tenant ID
- Tenant name
- The SSO provider you want to use (e.g. Azure AD, Auth0, Okta)

**Step 2: Prepare the Application on the IdP Side**

On your identity provider:

- Create an OIDC or SAML application/client according to your IdP’s requirements
- Collect the following details:
  
    - Client ID
    - Client Secret
    - Discovery URL / metadata endpoint  
      (for example:  
      `https://login.microsoftonline.com/{tenant}/v2.0/.well-known/openid-configuration`)

**Step 3: Share the Details with Parashift**

Send the following information to Parashift Support:

- Client ID
- Client Secret
- Discovery URL or metadata endpoint
- Indication of which IDP should be used
- Confirmation of the callback/redirect URI, if required  
  (e.g. `https://id.parashift.io/oidc/sso_callback`)

Parashift Support will then complete the internal configuration and link the SSO provider to your tenant.

**Ongoing Maintenance**

- Users will log in using the “Log in with SSO” button.
- Your admin team is responsible for:
  
    - Rotating the client secret
    - Providing the updated secret to Parashift Support before it expires

⚠️ Secret rotation is mandatory to avoid login disruptions.

 

*Note: SSO is only available for customers with a Parashift Endclient Subscription.* 

Learn more: [Tenant Security Management](https://support.parashift.io/tenant-security-management?hsLang=en)

- [Getting Started](https://support.parashift.io/getting-started?hsLang=en)
- [User Guides](https://support.parashift.io/user-guides?hsLang=en#main-content)

    - [General](https://support.parashift.io/user-guides?hsLang=en#general)
    - [Validation](https://support.parashift.io/user-guides?hsLang=en#validation)
    - [Platform Workshops](https://support.parashift.io/user-guides?hsLang=en#platform-workshops)
- [Configuration Guides](https://support.parashift.io/configuration-guides?hsLang=en#main-content)

    - [Document Type & Fields](https://support.parashift.io/configuration-guides?hsLang=en#document-type-fields)
    - [Automation](https://support.parashift.io/configuration-guides?hsLang=en#automation)
    - [Tenant (User management)](https://support.parashift.io/configuration-guides?hsLang=en#tenant-user-management)
    - [Workflow (Upload Configuration, Separation, Classification)](https://support.parashift.io/configuration-guides?hsLang=en#workflow-upload-configuration-separation-classification)
- [Release Notes](https://support.parashift.io/release-notes?hsLang=en)
- [API Documentation](https://support.parashift.io/api-documentation?hsLang=en#main-content)

    - [Platform API Configuration](https://support.parashift.io/api-documentation?hsLang=en#platform-api-configuration)
    - [Technical API Documentation](https://support.parashift.io/api-documentation?hsLang=en#technical-api-documentation)
- [Professional Services](https://support.parashift.io/professional-services?hsLang=en#main-content)

    - [Project-based Service Packages](https://support.parashift.io/professional-services?hsLang=en#project-based-service-packages)
    - [Subscription-based Service Packages](https://support.parashift.io/professional-services?hsLang=en#subscription-based-service-packages)

[![Knowledge Base Home](https://support.parashift.io/hubfs/parashift_logo_black-2.svg "Knowledge Base Home")](https://support.parashift.io/?hsLang=en)

[Platform Live Status](https://status.parashift.io/)   |   [API Documentation](https://docs.parashift.io/)

<https://www.parashift.io/> [mailto:support@parashift.io](mailto:support@parashift.io) <https://www.linkedin.com/company/parashiftag>

Copyright © 2025, Parashift AG