Documentation Index
Fetch the complete documentation index at: https://help.maestra.io/llms.txt
Use this file to discover all available pages before exploring further.
What is SSO?
Single Sign-On (SSO) is an authentication method that allows users to use one set of login credentials to access multiple applications. This solution helps centrally manage employee access and ensure data security. Maestra SSO is based on SAML 2.0 and uses an Identity Provider (IdP) managed by your company’s IT team.SAML (Security Assertion Markup Language) 2.0 is a protocol for exchanging authentication information between a service and an identity provider.An Identity Provider (IdP) is a system that creates, stores, and manages digital identification data. The IdP can either authenticate the user directly or provide authentication services to third-party providers (applications, websites, or other digital services).Examples of IdPs include Google, Azure AD, Okta, OneLogin.
Advantages of SSO
- Helps manage employee access to applications. It can be easily revoked if a user leaves the organization.
- Eliminates the need for employees to remember a large number of passwords for each service.
- Allows to change the password once to restore access to all applications if a user’s data has been compromised.
Log in with SSO
Users can be restricted to log in with SSO only or have the option to sign in with a Maestra username and password.

- The user clicks “Log in with SSO.”
- Maestra redirects them to your IdP.
- They enter login credentials in the IdP.
- The IdP redirects them back to Maestra.
- Maestra authenticates the user.
Users added to the project before SSO is enabled will also need to enter their Maestra password once to confirm their identity.
User Creation
If SSO is enabled when adding users to the project, they will be able to use it for authentication immediately. In this case, users will not receive an email with a password.Blocking users
To block access to the platform:- Block the user in your IdP.
- Block the user in Maestra.
Disabling SSO
When SSO is disabled, access to the project will be available to any staff member who has not been blocked in Maestra. Users without a password will need to use the password recovery feature.Technical requirements for SSO implementation
To use Maestra SSO, you need the following:- An enabled Enterprise-security module;
- An Identity Provider that supports the SAML 2.0 protocol.
Setting up SSO
Please note that SSO can only be configured and enabled by the project Owner.
- Go to Administrative settings → Platform → SSO Settings:

- Copy the ACS (Access Control Server) and Entity ID and paste them into the corresponding fields in your IdP settings.
- Select the user identification (Name ID) method: email address or login.
- Copy your IdP metadata and paste it into the corresponding block.
- Metadata URL
- Metadata XML
- Enable SSO — the button is located in the upper right corner of the screen.
- Check that the setting works correctly.
- Once you’ve ensured that everything works, you can enable SSO-only login.