SSO / SAML Setup

Configure enterprise single sign-on for your Refrax organization. Available on Teams plans ($49/mo) and above.

Refrax SP Details

Entity ID: https://app.refrax.onl/auth/saml/metadata

ACS URL: https://app.refrax.onl/auth/saml/acs

Metadata URL: https://app.refrax.onl/auth/saml/metadata

Okta

  1. In Okta Admin, go to Applications → Create App Integration
  2. Select SAML 2.0, enter Refrax as the app name
  3. Single sign-on URL: https://app.refrax.onl/auth/saml/acs
  4. Audience URI: https://app.refrax.onl/auth/saml/metadata
  5. Add attribute statements: email → user.email, name → user.displayName
  6. Assign users/groups and copy the IdP metadata URL
  7. In Refrax Settings → Security, paste Entity ID, SSO URL, and x509 certificate

Azure AD (Entra ID)

  1. Azure Portal → Enterprise Applications → New application → Non-gallery
  2. Configure Single sign-on → SAML
  3. Identifier: https://app.refrax.onl/auth/saml/metadata
  4. Reply URL: https://app.refrax.onl/auth/saml/acs
  5. Download Federation Metadata XML or copy App Federation Metadata Url
  6. In Refrax Settings → Security, configure IdP details
  7. Verify your domain with DNS TXT record: refrax-verify=<token>

Domain verification & enforce SSO

After configuring SAML, verify domain ownership in Settings → Security. Once verified, enable “Enforce SSO” to block password login for users with matching email domains.