SAML 2.0 SSO
Per-tenant SAML 2.0 with signed AuthnRequests, Upstash-backed replay cache, and single-sign-out in both directions.
- ·Signed AuthnRequests for Entra strict mode
- ·Just-in-time provisioning with role locked to IdP defaultRole
- ·Single-sign-out (both directions)
- ·Accept IdP-side role attribute claims (privilege-escalation guard)
- ·Sync group memberships (handled by your IdP)
- Auth
- SAML 2.0 + signed assertions
- Tier
- Standard, Campus