Setup guide
Set up single sign-on
Last updated: September 29, 2026
For company admins. Single sign-on lets your people sign in to Loomrail with their work account, and lets you require it for your email domain. Everything below is in Loomrail under Settings → Company → Sign-in. To add and remove people automatically as well, see automatic provisioning (SCIM).
1. Verify your email domain
Under Verified domains, add your domain (for example yourcompany.com). Loomrail shows a TXT record: add it to your domain's DNS, then press Check. Public email domains such as gmail.com can't be verified.
2. Choose how your people sign in
| Your company uses | Choose | What you set up |
|---|---|---|
| Google Workspace | Google Workspace | Nothing else — people use Continue with Google. |
| Microsoft 365 / Entra ID | Microsoft | Link your own Microsoft work account once (Your Microsoft account → Link), so Loomrail knows your organisation. People use Continue with Microsoft. |
| Okta, OneLogin, Ping, JumpCloud, or Entra / Google set up as a SAML app | SAML (Okta and others) | A SAML app in your identity provider — see step 3. |
3. SAML: connect your identity provider
In Loomrail, the Single sign-on with SAML section shows three values for your company: the Sign-on URL (ACS), the Audience / Entity ID and a Metadata URL. Create a SAML app in your identity provider with them, sending the person's email address as the Name ID. Menu names below can differ slightly between versions.
Okta
- Admin Console → Applications → Create App Integration → SAML 2.0.
- Single sign-on URL: Loomrail's Sign-on URL (ACS). Audience URI (SP Entity ID): Loomrail's Audience / Entity ID.
- Name ID format: EmailAddress. Application username: Email. Optionally add an attribute
displayNamewith the person's full name. - Finish, then on the app's Sign On tab copy the identity provider metadata and paste it into Loomrail (Paste metadata XML → Save).
- Assign the app to the people or groups who should use Loomrail.
Microsoft Entra ID (as a SAML app)
- Entra admin center → Enterprise applications → New application → Create your own application → integrate any other application (non-gallery).
- Single sign-on → SAML. Basic SAML Configuration: Identifier (Entity ID) = Loomrail's Audience / Entity ID; Reply URL = Loomrail's Sign-on URL (ACS).
- Attributes & Claims: set the Unique User Identifier (Name ID) to the user's email (
user.mail, oruser.userprincipalnameif that is their email), format Email address. - SAML Certificates: download Federation Metadata XML and paste it into Loomrail.
- Users and groups: assign the people who should use Loomrail.
Google Workspace (as a SAML app)
- Admin console → Apps → Web and mobile apps → Add app → Add custom SAML app, and download the IdP metadata.
- ACS URL and Entity ID: Loomrail's values. Name ID format: EMAIL; Name ID: Basic Information → Primary email.
- Paste the metadata into Loomrail, then turn the app on for your people.
Any other SAML provider: use the same three values, send the email as the Name ID, and sign the assertion (or the whole response). If your provider can't give metadata XML, choose Enter by hand and fill in its sign-in URL, entity ID and signing certificate.
4. Test, then require it
- Set your verified domain's Company sign-in to your provider.
- Press Sign in with SSO to sign in once yourself. Loomrail requires this before you can require single sign-on, so you can't lock yourself out.
- Optionally turn on Require it: passwords and personal accounts stop working for your domain, and everyone on it is signed out once and signs back in through your provider.
- Optionally turn on Add people automatically, so anyone who signs in with your domain joins your company.
People sign in from Loomrail's sign-in page with Sign in with SSO, or by opening Loomrail from your identity provider's app dashboard.
5. How it's kept safe
- Every SAML response must be signed by your identity provider's certificate; each is accepted once, only for Loomrail, and only while it's fresh.
- Your identity provider can only sign in people with an email on your verified domains.
- Changes to sign-in settings are recorded in your company's audit log. When your provider's certificate is renewed, paste the new metadata (Replace).
Questions: support@loomrail.com. See also Security.