Skip to main content

Overview

You are setting up Klarity Architect for your organisation and need to configure SSO so your users can log in with their company credentials. Klarity offers a self-serve SSO setup — a fully guided, in-product wizard that walks you through the configuration end to end. You may be using Microsoft Entra ID (Azure AD), Okta, Google Workspace, PingFederate, or any other SAML 2.0 / OIDC provider. SSO is not enabled by default. It must be configured once in your identity provider and once on the Klarity side. With self-serve setup, you complete both sides yourself through a guided wizard you open from a setup link we email you — no manual back-and-forth with Klarity support is required.

Prerequisites

Elect one individual to run the SSO setup with Klarity for your organisation. Before that person begins, make sure they have:
  1. Admin access to your organisation’s identity provider. Klarity’s setup flow supports any IdP that speaks SAML 2.0. Explicitly tested and guided paths:
    • Microsoft Entra ID (Azure AD)
    • Okta
    • Google Workspace
    • PingFederate (via the Generic SAML 2.0 path)
    • Any other SAML 2.0 IdP (via the Generic SAML 2.0 path)
    Custom OIDC paths are also supported.
  2. The list of email domains they want to enable SSO for (for example, company.com).

Step 1: Check your inbox for the SSO setup email

Search your inbox for an email with the subject “Set up SSO for [your domain] on Klarity”, sent from Klarity Architect (architect@klarity.ai). The email contains a “Set up SSO for [your domain]” button that opens the admin portal and connects your identity provider. The button works for 7 days — if you don’t finish in one sitting, just reopen the email and click it again to pick up exactly where you left off.
The automated 'Set up SSO for [your domain] on Klarity' email from Klarity Architect, containing the setup button that opens the admin portal to connect your identity provider.
Clicking the “Set up SSO for [your domain]” button opens our SSO setup experience — a fully guided flow that walks you through each step one by one:
  1. Select your identity provider from the list (Okta SAML, Entra ID / Azure AD SAML, Google SAML, and many more), or choose Custom SAML or Custom OIDC for any provider not listed.
  2. Follow the provider-specific, in-wizard instructions to create the integration in your IdP. For Okta SAML, for example: create a SAML integration, submit application feedback, set the IdP metadata, configure SAML attributes, assign groups, and test.
  3. Complete each step in sequence. At the end, your SSO connection is configured and your users can log in to Klarity with your organisation’s SSO.
The 'Select your identity provider' screen in the Klarity SSO setup wizard, listing providers such as Okta SAML, Entra ID (Azure AD) SAML, and Google SAML, with Custom SAML and Custom OIDC options at the bottom.
Klarity supports all the identity providers listed above. The wizard adapts its instructions to the provider you select.
The Okta SAML configuration step of the Klarity SSO setup wizard, showing the guided steps to create a SAML integration in the Okta admin console.

Step 3: Test your SSO connection

  1. Go to app.klarity.ai and enter your email.
    • This is a validation test — even if the email belongs to a new user who isn’t yet part of Klarity, the redirection will still work.
  2. Klarity redirects you to your organisation’s SSO and logs you in.
Once the test passes, the connection is live and all users in that domain sign in via SSO.
The Klarity Architect login screen used to validate an SSO connection, where the user enters their email at app.klarity.ai to be redirected to their organization's SSO.

When to contact support

Contact support if:
  • You don’t receive the SSO setup email, or the setup link has expired.
  • Your identity provider isn’t listed and you’re unsure whether to use the Generic SAML 2.0 or Custom OIDC path.
  • The connection test fails or your users can’t log in after setup.
When you contact support, include: your organisation name, the domain being configured, your IdP type, and a screenshot of the error, if any.

Frequently asked questions

Nothing, once the connection is re-established. They continue to sign in through your SSO exactly as they do today. MFA and session policies remain governed by your IdP.
The guided setup typically takes 15–20 minutes for someone with the right access. The main lead time is usually your internal intake/approval process.
No. We coordinate the cutover with your IT contact to keep the switch seamless — users with active sessions are unaffected, and new logins flow through the new connection once it’s validated.
Your identity provider, exactly as today. Klarity adds no additional MFA layer on top of your SSO.
No. Workspaces, processes, documents, roles, and permissions are untouched. Only the authentication connection changes.
Reach out to your Klarity customer success manager or support@klarity.ai with your organization name, the domain being configured, your IdP type, and a screenshot of the error — we can re-issue the setup link or restart the configuration at any time.