Paxos supports Service Provider (SP) initiated login only.
Questions? Contact Support.
Prerequisites
- An OIDC or SAML Identity Provider already configured in your organization
- At least one user who can complete Passkey onboarding to serve as the initial Organization Administrator
➊ Complete Passkey Onboarding
Before SSO can be configured, at least one user must create a Paxos account using passkeys and complete onboarding.We recommend completing the full SSO setup and login validation in the Sandbox environment before configuring production.
➋ Gather Your IdP Details
Collect the following information from your Identity Provider. You will send this to Paxos Support via SendSafely secure upload.- SAML
- OIDC
Required SAML attribute mappings (case-sensitive):
Additional requirements:
- Metadata must include HTTP-Redirect binding support
- Assertion encryption is enabled by default (can be disabled on request)
➌ Submit a Support Ticket
Open a ticket with Paxos Support indicating you want to migrate to SSO and your preferred protocol (SAML or OIDC). Send the required details from Step ➋ via SendSafely secure upload.➍ Configure Your IdP with Paxos Details
Paxos Support will respond with the configuration values you need to complete setup in your IdP, sent via SendSafely secure upload.- SAML
- OIDC
Paxos will provide:
Configure the following settings in your IdP:
➎ Complete First Login and Map Roles
An Organization Administrator must be the first person to log in after SSO is configured. This unlocks the Role Mapping interface.- Go to the Dashboard and select Continue with SSO.
- Once signed in, navigate to Admin > Team Management > Mapping.
- Map your IdP groups to Paxos Dashboard roles. See Team Access for mapping instructions.
Next Steps
- Manage Team Access — add role mappings and manage user permissions
- Dashboard Roles — review available roles and their permissions
- Sign In to Dashboard — share sign-in instructions with your team