SSO for your workspace
Configure Single Sign-On (SSO) for your bldrAgent workspace using Google Workspace, Okta, or any SAML 2.0 provider.
Single Sign-On (SSO)
SSO allows your team to sign in to bldrAgent using your existing identity provider — no separate bldrAgent password needed. This improves security and simplifies IT management.
SSO is available on the Enterprise plan only.
Supported identity providers
- Google Workspace (OAuth 2.0)
- Microsoft Entra ID (formerly Azure AD) — SAML 2.0
- Okta — SAML 2.0
- OneLogin — SAML 2.0
- Any SAML 2.0 compliant provider
Setting up SSO
Step 1 — Open SSO settings
Workspace Settings → Security → Single Sign-On
Step 2 — Copy the Service Provider details
bldrAgent will show you:
- Entity ID / Audience URI — e.g.
https://bldr.app/saml/yourworkspace - ACS URL (Assertion Consumer Service URL) — where your IdP sends the SAML response
- Metadata URL — for providers that support metadata import
Step 3 — Configure your identity provider
In your IdP (e.g. Okta), create a new SAML 2.0 application:
- Set the ACS URL from Step 2 as the Single sign-on URL
- Set the Entity ID as the Audience Restriction
- Map the following attributes:
email→ user's email addressfirstName→ user's first namelastName→ user's last namerole(optional) → maps to bldrAgent workspace role
Step 4 — Enter IdP details in bldrAgent
Back in bldrAgent, enter:
- Your IdP's SSO URL (the URL bldrAgent redirects to for login)
- Your IdP's X.509 certificate (public key for verifying SAML responses)
Step 5 — Test and enable
Click Test SSO to verify the configuration works, then toggle Enable SSO on.
SSO enforcement
Once SSO is enabled, you can optionally enforce it — meaning users can only sign in via SSO and not with their email/password:
Workspace Settings → Security → Enforce SSO
Before enforcing, ensure all workspace members have accounts in your IdP.
SCIM provisioning (auto-sync members)
With SCIM, your IdP automatically creates and deactivates bldrAgent workspace members when you add or remove users in your directory:
- Workspace Settings → Security → SCIM
- Generate a SCIM token
- Add the bldrAgent SCIM base URL and token to your IdP
- Map groups/users to your bldrAgent workspace
SCIM is supported with Okta and Microsoft Entra ID.
