Requirements
- Advanced Authentication and Security
Set up single sign-on (SSO) with a SAML provider to give everyone in your organization access to Robin. Robin supports IDP-initiated or SP-initiated flow through a custom configuration, with native provider support for Okta, OneLogin and Rippling.
SAML authentication is available for organizations with Advanced Authentication and Security. All other accounts can use SSO with Google and Microsoft 365.
Guides are available for these providers:
- Google Workspace
- Okta
- Delinea (formerly Centrify)
- ADFS
- Microsoft Entra ID (formerly Azure Active Directory)
- Rippling (set up through the Rippling integration)
- Custom (works with everything)
Add your identity provider to Robin
As an administrator, go to Manage > Integrations. The SAML 2.0 row is in the first card, Authentication methods.
Select Add to open the configuration options.
Configure your identity provider
Fill in a few fields in your IDP to connect it to Robin. If you are not sure which configuration to use, or a provider's connector app gives you trouble, use Custom.
For more settings, select the Advanced Options link. Most IDPs do not need them.
Required metadata attributes
Need XML to copy and paste? Download SP Metadata
Map these attributes to the matching user fields in your IDP. Only Email is required. FirstName and LastName are optional. Attribute names are case-sensitive. If you cannot change your attribute names, try assigning these to FriendlyName instead.
Robin also accepts these names for the first name: first_name, firstname, firstName and User.FirstName. For the last name, it accepts last_name, lastname, lastName and User.LastName.
NameID
<saml:NameID Format="urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress">
testuser@youremail.com
</saml:NameID>Handling Invalid NameID
By default, Robin asks your IDP for an encrypted NameID (urn:oasis:names:tc:SAML:2.0:nameid-format:encrypted). This is because Encrypt Assertion is on by default under Advanced Options. While Encrypt Assertion is on, Robin asks for an encrypted NameID, whatever the Encrypt NameID attribute box says. When Encrypt Assertion is off, Robin asks for the email address format (urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress). Robin identifies the user by the Email attribute, not by the NameID.
If your IDP logs show InvalidNameIDPolicy errors, uncheck Encrypt Assertion under Advanced Options, or set up your IDP to encrypt the NameID.
<saml:Attribute Name="Email" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified">
<saml:AttributeValue xsi:type="xs:anyType">testuser@youremail.com</saml:AttributeValue>
</saml:Attribute>FirstName
<saml:Attribute Name="FirstName" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified">
<saml:AttributeValue xsi:type="xs:anyType">Jane</saml:AttributeValue>
</saml:Attribute>LastName
<saml:Attribute Name="LastName" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:unspecified">
<saml:AttributeValue xsi:type="xs:anyType">Smith</saml:AttributeValue>
</saml:Attribute>Custom provider
Need XML to copy and paste? Download SP Metadata
Use the fields below or the metadata file above to get started. If your IDP uses different names for the metadata attributes, map them.
- Entity ID (Issuer): https://robinpowered.com
- SSO (ACS) URL: https://dashboard.robinpowered.com/sso/saml/custom
- Relay State (Optional): https://dashboard.robinpowered.com/auth/saml
- Encrypt Assertion is on by default under Advanced Options. With it on, Robin signs its sign-in requests and asks for an encrypted NameID. If your identity provider (for example ADFS) cannot handle signed requests or encrypt the NameID, uncheck Encrypt Assertion. Otherwise, sign-ins that start from Robin can fail. When it is off, Robin stops signing requests and ignores Encrypt NameID attribute, even if that box stays checked.
-
Robin's Public Key (x509 cert): copy the certificate below.
-----BEGIN CERTIFICATE----- MIICtjCCAh+gAwIBAgIUeTzNrcUw+kyMMormmeinC5f6MxgwDQYJKoZIhvcNAQEL BQAwbDELMAkGA1UEBhMCVVMxFjAUBgNVBAgMDU1hc3NhY2h1c2V0dHMxDzANBgNV BAcMBkJvc3RvbjEZMBcGA1UECgwQUm9iaW4gUG93ZXJlZCBJbjEZMBcGA1UEAwwQ cm9iaW5wb3dlcmVkLmNvbTAgFw0yNTExMTkyMTQwMTZaGA8yMTI0MTAyNjIxNDAx NlowbDELMAkGA1UEBhMCVVMxFjAUBgNVBAgMDU1hc3NhY2h1c2V0dHMxDzANBgNV BAcMBkJvc3RvbjEZMBcGA1UECgwQUm9iaW4gUG93ZXJlZCBJbjEZMBcGA1UEAwwQ cm9iaW5wb3dlcmVkLmNvbTCBnzANBgkqhkiG9w0BAQEFAAOBjQAwgYkCgYEAuiqF +VDUiqzno9/DxbNfqjBxuimuONafe3vj2pY0uDoMK4YqSxUhbM1vWzsD+VE/fT4v WItgBgHLHbacdXBC1Q6bldr6cvrNt+5EWDXM515VXpcGdR/Gnmy8DRQO5PbxMlY+ 91YNxJC6sV+WOEiKj/+VN/JTMytFEI5A66xIxhUCAwEAAaNTMFEwHQYDVR0OBBYE FOLPYJrHGWowwXqLXR6QrcWjpvpCMB8GA1UdIwQYMBaAFOLPYJrHGWowwXqLXR6Q rcWjpvpCMA8GA1UdEwEB/wQFMAMBAf8wDQYJKoZIhvcNAQELBQADgYEAlICAw5Gt 0STxEXRfQWM9L5Ij/y/JZrb//YPy5n5SWrPT+g4tkAYw9k+juCit0xQ2ZeHleyV/ K94vYfOcCwegbkLJDfktbzlJxTWgb6cl71tbw0H5b/v8dNxGIh+1BYT5xuWjbecD 92oyqAFCDk4RltbxBD1Hvn52CtTEEIUUm2g= -----END CERTIFICATE-----
Download the x509 cert instead Download Certificate
Azure
Follow the steps above. Then, under Advanced options, do this:
- Uncheck every box. Under Auth Context, uncheck all boxes. Password Protected Transport is the only one checked by default. Also uncheck Encrypt Assertion and Encrypt NameID attribute. If any box stays checked, users can get errors when they sign in.
Okta
Okta has its own guide. See Enabling single sign-on via Okta.
Google Workspace
Google SAML has its own guide. See single sign-on with SAML for Google Workspace.
Delinea (formerly Centrify)
Follow the main guide above, and use this script to map the custom attributes:
setIssuer(Issuer);
setSubjectName(UserIdentifier);
setAudience('https://robinpowered.com');
setRecipient(ServiceUrl);
setHttpDestination(ServiceUrl);
setSignatureType('Response');
setNameFormat('emailAddress');
var FirstName = LoginUser.Get('GivenName');
var LastName = LoginUser.Get('sn');
var Email = LoginUser.Get('mail');
// Map IDP attributes to Robin
setAttribute('FirstName',FirstName);
setAttribute('LastName',LastName);
setAttribute('Email',Email);
// Optional for testing within Centrify
trace("FirstName is" + " " + FirstName);
trace("LastName is" + ' ' + LastName);
trace("Email is" + " " + Email);
Sign in with SAML
Members in your organization sign in on the login page. They enter their email address and select Continue. If their email address belongs to more than one organization, they choose one. Then they select the single sign-on button. For Okta, OneLogin or Rippling, the button shows the provider's name. For a custom provider, it says Single Sign-On.
You can also link directly to your SAML sign-in page to start SP-authentication right away: https://dashboard.robinpowered.com/login/saml/yourcompany. Replace "yourcompany" with your organization's username. Members need to know your organization's username (for example, "robin" or "acme-inc") to start authentication with your SAML provider.
Troubleshooting
If you have trouble setting up your SAML configuration, contact the Robin support team for help.