Skip to main content
Single Sign-On (SSO) lets your team authenticate into the Paxos Dashboard using your organization’s existing identity provider (IdP) — such as Okta, Microsoft Entra, PingFederate, or Active Directory — instead of managing individual passkeys. Paxos supports SAML and OIDC protocols. OIDC is simpler to configure and less error-prone; use it when your IdP supports both options.
Paxos supports Service Provider (SP) initiated login only.
Questions? Contact Support.

Prerequisites

  • An OIDC or SAML Identity Provider already configured in your organization
  • At least one user who can complete Passkey onboarding to serve as the initial Organization Administrator

➊ Complete Passkey Onboarding

Before SSO can be configured, at least one user must create a Paxos account using passkeys and complete onboarding.
Passkey access is disabled for all users when SSO goes live. Paxos Support removes passkey authentication for your entire organization as part of the SSO configuration process — it is not a gradual transition. After SSO is activated, users who attempt to sign in with a passkey will no longer be able to do so.Notify your team of the cutover date before SSO is enabled so they are prepared to use Continue with SSO from their first sign-in after the switch.
We recommend completing the full SSO setup and login validation in the Sandbox environment before configuring production.

➋ Gather Your IdP Details

Collect the following information from your Identity Provider. You will send this to Paxos Support via SendSafely secure upload.
Required SAML attribute mappings (case-sensitive):Additional requirements:
  • Metadata must include HTTP-Redirect binding support
  • Assertion encryption is enabled by default (can be disabled on request)

➌ Submit a Support Ticket

Open a ticket with Paxos Support indicating you want to migrate to SSO and your preferred protocol (SAML or OIDC). Send the required details from Step ➋ via SendSafely secure upload.

➍ Configure Your IdP with Paxos Details

Paxos Support will respond with the configuration values you need to complete setup in your IdP, sent via SendSafely secure upload.
Paxos will provide:Configure the following settings in your IdP:

➎ Complete First Login and Map Roles

An Organization Administrator must be the first person to log in after SSO is configured. This unlocks the Role Mapping interface.
  1. Go to the Dashboard and select Continue with SSO.
  2. Once signed in, navigate to Admin > Team Management > Mapping.
  3. Map your IdP groups to Paxos Dashboard roles. See Team Access for mapping instructions.
Non-admin users will see a 403 Forbidden error until role mappings are configured. Complete role mapping before notifying your team.Role mappings are per Entity. If your organization has multiple Entities, you must configure mappings separately for each.

Next Steps