Skip to content

Set up Single Sign-On

Single Sign-On (SSO) lets your team sign in to HIVE with your own identity provider - such as Microsoft Entra ID, Okta, or Google Workspace - instead of a separate HIVE password. You configure the connection once, and from then on your people sign in through your identity provider.

You’ll need a few things in place:

  1. Your HIVE organisation on the Enterprise package, with SSO enabled by HIVE (see the note above).
  2. Administrator access to your identity provider (Entra ID, Okta, Google Workspace, OneLogin, Ping, JumpCloud, or any provider that supports OIDC or SAML 2.0).
  3. Admin access in HIVE - SSO settings live under an admin-only tab. If you don’t see it, ask whoever manages your HIVE account to make you an admin, or contact HIVE.

Once HIVE has enabled SSO for your organisation, you’ll find a new Single Sign-On tab under Settings.

You configure SSO from inside HIVE, in a secure setup portal that opens in a new tab.

  1. In HIVE, go to Settings → Single Sign-On. You’ll see your organisation’s status and the email domains SSO applies to.

  2. Select Configure SSO. The secure setup portal opens in a new browser tab.

  3. In the portal, choose your identity provider and the protocol it uses - OIDC or SAML 2.0. If you’re not sure which to use, OIDC is usually the simpler option where your provider supports it.

  4. Follow the portal’s step-by-step guide for your provider. It will give you the values to enter in your identity provider (such as a redirect URL and an identifier), and ask you to paste back the details from your provider. For the exact steps on your side, follow your identity provider’s own SSO documentation - it’s the most up-to-date source for your platform.

  5. Make sure your provider passes the user’s email (and, ideally, first and last name) in the sign-in details - HIVE uses the email to identify each person.

  6. Use the portal’s Test Connection to confirm everything is wired up, then enable the connection.

Before you ask everyone to switch, confirm a real sign-in works.

  1. On the Single Sign-On tab, once your status is Active, select Test SSO login. It opens the sign-in flow in a new tab using your own email address.

  2. Complete the sign-in through your identity provider. If it lands you back in HIVE, your connection is working.

Once SSO is active:

  • Your people go to the HIVE sign-in page, enter their work email, and are sent to your identity provider to sign in - HIVE never sees their password.
  • The first time someone signs in via SSO, HIVE creates their account automatically as a Viewer. An admin can then adjust their role (Viewer, Editor, or Admin) under Settings → Team & Roles. See Getting Started for what each role can do.
  • Signing in via SSO doesn’t use up an editor licence on its own - new people arrive as Viewers.

You can turn your existing connection off and on yourself from the setup portal - useful if you need to pause SSO temporarily.

Switching to a different identity provider or protocol (for example, moving from SAML to OIDC, or migrating to a new provider) needs a fresh connection, which HIVE sets up for you. Contact HIVE and we’ll clear the old connection so you can configure the new one.