Who can use this feature?
In this article, we will walk through the required steps to integrate your Identity Provider (IdP) SSO with Chili Piper.
⚠️ Changing an SSO user's email? Read this first.
If your organization signs in to Chili Piper with SSO/SAML, do not change a user's email by simply signing in with the new address. Chili Piper currently matches SSO users by their email address, so renaming a user in your identity provider can create a new, empty Chili Piper account and leave the original account's meetings, calendar connection, and routing behind.
Before renaming a user in your identity provider, contact your Customer Success Manager or support@chilipiper.com, so we can help you with the process.
Table of Contents
- Things to Know
- How to configure SAML SSO for your Identity Provider
- SAML Features
- SAML Attributes include
Things to Know
- You must be a Chili Piper admin to enable Single Sign-On (SSO).
- You must use the same email address for both Chili Piper and your IdP.
- Renaming a user / changing a user's email: Chili Piper currently matches users by email address, so renaming a user's email in your identity provider will create a new Chili Piper account and orphan the old one (along with its meetings, calendar connection, and routing). We recommend contacting your Customer Success Manager or support@chilipiper.com before renaming an SSO user.
Chili Piper supports any enterprise identity provider (IdP) using the SAML 2.0 protocol. We have tested and documented SAML SSO setup instructions for the following identity providers: Okta
Since steps may vary by identity provider, consult the documentation from your identity provider for more information.
How to configure SAML SSO for your Identity Provider
-
In the Command Center, access SAML Configuration by clicking Integrations in the left-side menu and clicking the Single Sign-On tab. Then click Connect on the Single Sign-On card.
-
Copy and Paste the Single Sign-On and the SP Entity ID from Chili Piper into your Identity Provider. These URLS cannot be edited in anyway or they will not work.
Your Identity provider may refer to the Single Sign-On field as- Default ACS
- Reply URL
- Application Callback URL
- SAML Consumer URL
Your Identity provider may refer to the Entity ID field as:
- Audience URL
- Identifier
Some Identity Providers require Recipient/Destination: - A field called “recipient” or "destination"
- A checkbox to enable sending the ACS as the recipient & destination
- No field or checkbox - the IdP will automatically send the ACS URL as the recipient and destination
- Copy the metadata URL from your Identity Provider, and paste to Metadata URL field in Chili Piper in Step 2 section of the IdP setup:
If your identity provider has application restrictions for users, update those rules so you and the appropriate users can use Chili Piper.
In Chili Piper, click Test Connection and you will be directed to your IdP login screen. You must log into your IdP using the same credentials that you are logged into Chili Piper.
If the Connection is successful, you will be redirected back to Chili Piper to enforce SSO for all users.
-
If you want to enforce your users only logging in via your IdP, you can opt to do this now. This option will only be available if testing the connection in Step 2 was successful.
SAML Features
- SP login flow (Service-provider Initiated)
- User can login via fire.chiliipiper.com, and your Identity provider will authenticate the user
- Identity Provider Initiated SSO (IdP-initiated)
- Users can log in to their identity provider and select the Chili Piper app.
- Only available if your identity provider supports a Default Relay State.
- JIT provisioning is not supported.
SAML Attributes include:
- firstName: user.firstName
- lastName: user.lastName
- email: user.email
Comments
0 comments
Please sign in to leave a comment.