Skip to main content
SAML appears under Settings → Access only when the deployment has an active Enterprise entitlement. Only a workspace owner can configure it. Before changing the connection, sign in within the last ten minutes and verify your Tekma authenticator.

Configure the identity provider

  1. Open Settings → Access and review the values Tekma displays for ACS URL and Service provider entity ID.
  2. Create a SAML application in Okta, Microsoft Entra ID, Google Workspace, or another compatible provider using those values. Send a signed assertion with email and name attributes, a stable NameID, audience, recipient and timestamp conditions. Use SHA-256 or stronger.
  3. In Tekma, enter the Company email domain, Identity provider entity ID, and Identity provider sign-in URL. Paste the provider’s public signing certificate in PEM format; never paste a private key.
  4. Choose Save SAML configuration. Saving or replacing configuration disables SSO until DNS is verified again.

Verify and enable

Publish the _tekma-saml DNS proof shown by Tekma for the exact company domain. The proof is valid for seven days. Choose Verify DNS and enable SSO. Reverify the same record when it expires or when Tekma asks after a configuration change. Test the SP-initiated company sign-in in a separate window before directing teammates to it. Existing verified members can use company sign-in when the deployment enables that path. Password sign-in and Tekma MFA remain available; Tekma continues to manage membership and roles.

Limits and recovery

Tekma does not promise just-in-time account creation, IdP-initiated sign-in, enforced SSO, multiple domains, or single logout. If verification fails, confirm the exact domain, TXT proof, provider certificate and ACS/entity values, then retry after DNS propagation. Disabling SSO stops new SAML logins but does not terminate sessions that already exist.