Enabling single sign-on via SAML 2.0

Requirements

  • Advanced Authentication and Security

Set up single sign-on (SSO) with a SAML provider to give everyone in your organization access to Robin. Robin supports IDP-initiated or SP-initiated flow through a custom configuration, with native provider support for Okta, OneLogin and Rippling.

SAML authentication is available for organizations with Advanced Authentication and Security. All other accounts can use SSO with Google and Microsoft 365.

Guides are available for these providers:

Add your identity provider to Robin

As an administrator, go to Manage > Integrations. The SAML 2.0 row is in the first card, Authentication methods.

Select Add to open the configuration options.

Configure your identity provider

Fill in a few fields in your IDP to connect it to Robin. If you are not sure which configuration to use, or a provider's connector app gives you trouble, use Custom.

For more settings, select the Advanced Options link. Most IDPs do not need them.

Screenshot 2025-04-23 at 3.15.01 PM.png

Required metadata attributes

Need XML to copy and paste? Download SP Metadata

Map these attributes to the matching user fields in your IDP. Only Email is required. FirstName and LastName are optional. Attribute names are case-sensitive. If you cannot change your attribute names, try assigning these to FriendlyName instead.

Robin also accepts these names for the first name: first_name, firstname, firstName and User.FirstName. For the last name, it accepts last_name, lastname, lastName and User.LastName.

NameID

<saml:NameID Format="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress">
  testuser@youremail.com
</saml:NameID>

Handling Invalid NameID

robin-invalid-saml-nameidpolicy.png

By default, Robin asks your IDP for an encrypted NameID (urn:oasis:names:tc:SAML:2.0:nameid-format:encrypted). This is because Encrypt Assertion is on by default under Advanced Options. While Encrypt Assertion is on, Robin asks for an encrypted NameID, whatever the Encrypt NameID attribute box says. When Encrypt Assertion is off, Robin asks for the email address format (urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress). Robin identifies the user by the Email attribute, not by the NameID.

If your IDP logs show InvalidNameIDPolicy errors, uncheck Encrypt Assertion under Advanced Options, or set up your IDP to encrypt the NameID.

Email

<saml:Attribute Name="Email" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified">
  <saml:AttributeValue xsi:type="xs:anyType">testuser@youremail.com</saml:AttributeValue>
 </saml:Attribute>

FirstName

<saml:Attribute Name="FirstName" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified">
  <saml:AttributeValue xsi:type="xs:anyType">Jane</saml:AttributeValue>
</saml:Attribute>

LastName

<saml:Attribute Name="LastName" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified">
  <saml:AttributeValue xsi:type="xs:anyType">Smith</saml:AttributeValue>
</saml:Attribute>

Custom provider

Need XML to copy and paste? Download SP Metadata

Use the fields below or the metadata file above to get started. If your IDP uses different names for the metadata attributes, map them.

  • Entity ID (Issuer): https://robinpowered.com
  • SSO (ACS) URL: https://dashboard.robinpowered.com/sso/saml/custom
  • Relay State (Optional): https://dashboard.robinpowered.com/auth/saml
  • Encrypt Assertion is on by default under Advanced Options. With it on, Robin signs its sign-in requests and asks for an encrypted NameID. If your identity provider (for example ADFS) cannot handle signed requests or encrypt the NameID, uncheck Encrypt Assertion. Otherwise, sign-ins that start from Robin can fail. When it is off, Robin stops signing requests and ignores Encrypt NameID attribute, even if that box stays checked.
  • Robin's Public Key (x509 cert): copy the certificate below.

    -----BEGIN CERTIFICATE-----
    MIICtjCCAh+gAwIBAgIUeTzNrcUw+kyMMormmeinC5f6MxgwDQYJKoZIhvcNAQEL
    BQAwbDELMAkGA1UEBhMCVVMxFjAUBgNVBAgMDU1hc3NhY2h1c2V0dHMxDzANBgNV
    BAcMBkJvc3RvbjEZMBcGA1UECgwQUm9iaW4gUG93ZXJlZCBJbjEZMBcGA1UEAwwQ
    cm9iaW5wb3dlcmVkLmNvbTAgFw0yNTExMTkyMTQwMTZaGA8yMTI0MTAyNjIxNDAx
    NlowbDELMAkGA1UEBhMCVVMxFjAUBgNVBAgMDU1hc3NhY2h1c2V0dHMxDzANBgNV
    BAcMBkJvc3RvbjEZMBcGA1UECgwQUm9iaW4gUG93ZXJlZCBJbjEZMBcGA1UEAwwQ
    cm9iaW5wb3dlcmVkLmNvbTCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAuiqF
    +VDUiqzno9/DxbNfqjBxuimuONafe3vj2pY0uDoMK4YqSxUhbM1vWzsD+VE/fT4v
    WItgBgHLHbacdXBC1Q6bldr6cvrNt+5EWDXM515VXpcGdR/Gnmy8DRQO5PbxMlY+
    91YNxJC6sV+WOEiKj/+VN/JTMytFEI5A66xIxhUCAwEAAaNTMFEwHQYDVR0OBBYE
    FOLPYJrHGWowwXqLXR6QrcWjpvpCMB8GA1UdIwQYMBaAFOLPYJrHGWowwXqLXR6Q
    rcWjpvpCMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQELBQADgYEAlICAw5Gt
    0STxEXRfQWM9L5Ij/y/JZrb//YPy5n5SWrPT+g4tkAYw9k+juCit0xQ2ZeHleyV/
    K94vYfOcCwegbkLJDfktbzlJxTWgb6cl71tbw0H5b/v8dNxGIh+1BYT5xuWjbecD
    92oyqAFCDk4RltbxBD1Hvn52CtTEEIUUm2g=
    -----END CERTIFICATE-----

Download the x509 cert instead Download Certificate

Azure

Follow the steps above. Then, under Advanced options, do this:

  • Uncheck every box. Under Auth Context, uncheck all boxes. Password Protected Transport is the only one checked by default. Also uncheck Encrypt Assertion and Encrypt NameID attribute. If any box stays checked, users can get errors when they sign in.

Okta

Okta has its own guide. See Enabling single sign-on via Okta.

Google Workspace

Google SAML has its own guide. See single sign-on with SAML for Google Workspace.

Delinea (formerly Centrify)

Follow the main guide above, and use this script to map the custom attributes:

setIssuer(Issuer);
setSubjectName(UserIdentifier);
setAudience('https://robinpowered.com');
setRecipient(ServiceUrl);
setHttpDestination(ServiceUrl);

setSignatureType('Response');
setNameFormat('emailAddress');

var FirstName = LoginUser.Get('GivenName');
var LastName = LoginUser.Get('sn');
var Email = LoginUser.Get('mail');

// Map IDP attributes to Robin
setAttribute('FirstName',FirstName);
setAttribute('LastName',LastName);
setAttribute('Email',Email);

// Optional for testing within Centrify
trace("FirstName is" + " " + FirstName);
trace("LastName is" + ' ' + LastName);
trace("Email is" + " " + Email);

Sign in with SAML

Members in your organization sign in on the login page. They enter their email address and select Continue. If their email address belongs to more than one organization, they choose one. Then they select the single sign-on button. For Okta, OneLogin or Rippling, the button shows the provider's name. For a custom provider, it says Single Sign-On.

You can also link directly to your SAML sign-in page to start SP-authentication right away: https://dashboard.robinpowered.com/login/saml/yourcompany. Replace "yourcompany" with your organization's username. Members need to know your organization's username (for example, "robin" or "acme-inc") to start authentication with your SAML provider.

Screenshot 2026-07-21 at 1.49.53 PM.png
Screenshot 2026-07-21 at 1.50.37 PM.png

Troubleshooting

If you have trouble setting up your SAML configuration, contact the Robin support team for help.

Articles in this section

Was this article helpful?
2 out of 9 found this helpful
Share