Thank you! Your feedback helps us improve.

Superhuman single sign-on (SSO) uses the SAML 2.0 standard, which works with most common identity providers — so you can roll it out with the identity solution your organization already uses. This article walks you through the setup using Okta as the example. The same process works for any SAML 2.0 identity provider (Microsoft Entra ID, Google, OneLogin, and others), though the field names may be different.

Note: Before SSO can be enforced across your organization, your organization’s domain(s) must be verified by Superhuman. If your domains aren’t yet verified or you’re unsure, reach out to your Superhuman Customer Success Manager or contact Support.

Requirements

  • A Superhuman Enterprise subscription
  • Organization Admin access in Superhuman Admin Settings
  • Administrator access to your identity provider (for example, the Okta Admin Console)

Step 1: Find your setup details in Superhuman

  1. Go to the Authentication page.
  2. If SSO has not yet been configured, Superhuman displays your SP Entity ID and ACS URL. Keep these two values handy, since you’ll enter them into your identity provider in the next step.
image.png

Step 2: Create a SAML app in your identity provider

These steps use Okta as the example. If you use a different identity provider, create a new SAML 2.0 application and look for the matching fields.

  1. Sign in to the Okta Admin Console with your administrator account.
  2. Go to Applications, click Create App Integration, select SAML 2.0, and click Next.
  3. Enter an App name (for example, Superhuman), then click Next.
  4. On the Configure SAML page, enter the values shown on the Authentication page:
    • Single sign-on URL (ACS URL): your ACS URL
    • Audience URI (SP Entity ID): your SP Entity ID
    • Name ID format: EmailAddress
  5. Click Finish to create the application.
image.png

Step 3: Copy your identity provider details

To turn on SSO in Superhuman, you’ll need three values from your identity provider:

  • Identity Provider Issuer
  • SAML 2.0 Endpoint (the Sign-On / SSO URL)
  • Certificate (the X.509 signing certificate)

In Okta, open Applications, select the app you just created, and open the Sign On tab. Expand Metadata details (or View SAML setup instructions) to find all three values.

image.png

Step 4: Add the details to Superhuman

  1. Return to the Authentication page in Superhuman Admin Settings.
  2. Enter the Identity Provider Issuer, SAML 2.0 Endpoint, and the Certificate.
  3. Click Save, then click Activate SSO.
image.png

After activation, members of your organization will sign in to Superhuman through your identity provider.

Step 5: Give your team members access

  1. In Okta, open Applications and select the SAML app you created.
  2. Open the Assignments tab and choose Assign to People (or Assign to Groups).
  3. Select the users (or groups) who should have access, assign the app, and click Done.

Note: The domain of assigned users must match your organization’s verified domain.

Step 6: Test the configuration

  1. Before signing out of your Superhuman admin account, test the SSO configuration with a single user. Ensure that the user is assigned access to Superhuman in your identity provider and has an active account.
  2. Open a new incognito window in your browser and go to id.superhuman.com.
  3. Enter the test user’s email address and click Continue with email to be redirected to your identity provider for authentication.
  4. Sign in with the test user’s identity provider credentials. If it works, you’ll be redirected back to Superhuman. This confirms SSO is set up correctly.
  5. Once the test succeeds, proceed to assign access to other users in your identity provider.

If the test sign-in fails, double-check that the SP Entity ID and ACS URL in your identity provider match the values in Superhuman, that the Name ID format is set to EmailAddress, and that the test user is assigned access to Superhuman. If you’re still stuck, please contact Support.

Was this article helpful?

Tell us what you think. We promise to act on your feedback to make Grammarly's support pages even more helpful.
Have more questions? Submit a request