> ## Documentation Index
> Fetch the complete documentation index at: https://help.honestly.com/llms.txt
> Use this file to discover all available pages before exploring further.

# How can I register with Honestly via SSO?

> ”SAML - based single sign-on can be used to grant users access through an identity provider (IDP) of the client's choice.

”SAML - based single sign-on can be used to grant users access through an identity provider (IDP) of the client's choice. **This option is** **available to Enterprise Customers only and can be configured by admins**

#### Honestly: Service provider (SP)

| Item               | Description                                                                                                  |
| ------------------ | ------------------------------------------------------------------------------------------------------------ |
| Name               | Honestly                                                                                                     |
| Integration option | SAML 2.0                                                                                                     |
| Logo               | [https://www.honestly.com/images/logo-transparent.png](https://www.honestly.com/images/logo-transparent.png) |
| Time synchronised  | Europe/Berlin                                                                                                |
| NameId             | EmailAddress                                                                                                 |

**1. Click on: "Settings" and then on "Single Sign-On"**

<img src="https://mintcdn.com/honestly/iyFkM6_8NJ4WWHPk/images/4f66270b7558.png?fit=max&auto=format&n=iyFkM6_8NJ4WWHPk&q=85&s=82ea017318bde6fd4d84ed066dfd7141" alt="" width="233" height="687" data-path="images/4f66270b7558.png" />

**2. Now you can enable "SSO"**

<img src="https://mintcdn.com/honestly/iyFkM6_8NJ4WWHPk/images/657de28d9842.png?fit=max&auto=format&n=iyFkM6_8NJ4WWHPk&q=85&s=cd9f66798aee584c09f01442a0b0570e" alt="" width="1171" height="272" data-path="images/657de28d9842.png" />

**3. Enable SSO**

<img src="https://mintcdn.com/honestly/pfDC0-M9Pz06l2cT/images/707cfd49838b.png?fit=max&auto=format&n=pfDC0-M9Pz06l2cT&q=85&s=ca6f289bd4fe3b259af312c215acd0e4" alt="" width="1163" height="644" data-path="images/707cfd49838b.png" />

**4. Get all Information you need:**

* * Honestly ACS URL
* Honestly Entity ID

<img src="https://mintcdn.com/honestly/MJJuN9_M5LZfDZvk/images/c13d9bcaff82.png?fit=max&auto=format&n=MJJuN9_M5LZfDZvk&q=85&s=9e22410b324ac750383cf62b298ee329" alt="" width="943" height="101" data-path="images/c13d9bcaff82.png" />

**5. Share your Information within the Honestly Account**

* * SSO URL

* Entity ID

* * x509 Certificate .pem (base64 encoded)

<img src="https://mintcdn.com/honestly/RHnmdNI6i6v29PMC/images/17d71378b57a.png?fit=max&auto=format&n=RHnmdNI6i6v29PMC&q=85&s=88812bca0704427012fce67ad524d271" alt="" width="939" height="516" data-path="images/17d71378b57a.png" />

Please do not forget to start with: -----BEGIN CERTIFICATE-----\*\*

Please do not forget to end with: -----END CERTIFICATE-----

**6. Click on "SSO optional" for testing purpose**

**<img src="https://mintcdn.com/honestly/MJJuN9_M5LZfDZvk/images/ac64e0ec3a25.png?fit=max&auto=format&n=MJJuN9_M5LZfDZvk&q=85&s=d6056a0445e36a64867c63e50e487d37" alt="" width="1164" height="522" data-path="images/ac64e0ec3a25.png" />**

**7. Click on "Save"**

**8. Ready for testing**

**9. After successful testing, deactivate "SSO optional" setting in order to require all users to login via SSO**

**⚠️ Security Warning:**

Leaving SSO optional is a **security risk** , as users can still authenticate with local passwords instead of your identity provider. This bypasses key protections such as centralized access control, MFA, and automatic deprovisioning.

If a user is disabled in your identity provider, their account may still remain accessible. To avoid unauthorized access and ensure full security, **SSO should be enforced for all users**.

<Note />

If SSO is enabled, the user will no longer get a mail notification after getting a role that can log in to the Honestly platform.
