Managed SAML lets admitted users sign in through the identity provider for a
verified company domain. It is available on Business and is configured by a
workspace owner.
Before you start
Obtain:
The verified company domain
The identity provider issuer
Current identity provider metadata XML
Stackyapper supports one managed SAML domain per workspace. The domain must
already be verified for the organization.
Connect SAML
Open Settings → Identity & access.
Under Managed SAML, enter the verified domain and IdP issuer.
Paste the metadata XML published by the identity provider.
Save the connection.
Test sign-in with an admitted non-owner user.
Confirm the user reaches the intended workspace.
SAML authenticates an admitted user; it does not create tool grants or move a
user between workspaces.
Replace metadata
Use Edit to replace identity-provider metadata. The Stackyapper provider
identity, entity ID, and callback URL remain unchanged.
Keep an owner session available while testing replacement metadata. If sign-in
fails, restore correct provider metadata before ending the administrative
session.
Remove SAML
Removing the connection returns users to the workspace's standard sign-in
paths. Confirm those users have an appropriate sign-in method before removal,
then test the intended fallback.