Plan availability | Business and Enterprise Scale only |
Platform(s) | Web/Browser, Mac app, and Windows app |
Related reading |
Setting up SSO for OneLogin
Note
Before setting up SSO for OneLogin, ensure your OneLogin account is in "admin mode."
To set up SSO for OneLogin:
Login to OneLogin.
Click Apps, then Add Apps.
Search for and select "Airtable."
Add the "SAML2.0 app."
From the Airtable app page, click SSO.
Copy and paste the "X.509 Certificate" and the "SAML 2.0 Endpoint (HTTP)" as they are required for the next step.
Enter the "SAML 2.0 Endpoint (HTTP)" under "Sign On URL" and the "X.509 Certificate" under "x.509 Certificate", following the steps in the Configuring SSO in the admin panel article.
-1(1).png)
Note
By default, Airtable requires the NameID in the SAML assertion to be the user’s email address.
If your organization uses a non-email identifier (such as an employee ID) as the NameID, configure the email attribute in Airtable’s SSO settings so Airtable reads each user’s email address from the SAML attribute you specify — see SSO dependencies for more information.
The ACS URL and Entity ID for your configuration are shown in the SSO configuration dialog in the admin panel.
FAQs
If another team in my company already uses SSO with Airtable, how does this impact my Business or Enterprise Scale account?
In Airtable, our system expects Enterprise Scale accounts using shared domains—domains federated to multiple Enterprise accounts—to use the same SAML metadata for SSO. What this means is that if your company has existing Enterprise Scale accounts with SSO configured, you will need to coordinate with the admins (or IT department) of the other accounts to obtain the current sign-in URLs, x.509 certificates, and ensure that your users have the necessary access to the Airtable tenant present in your company’s identity provider.
You can configure separate tenants or identity providers for domains unique to Enterprise Scale accounts, as each domain can be configured with its own SAML metadata.