SSO / SAML Setup
Configure enterprise single sign-on for your Refrax organization. Available on Teams plans ($49/mo) and above.
Refrax SP Details
Entity ID: https://app.refrax.onl/auth/saml/metadata
ACS URL: https://app.refrax.onl/auth/saml/acs
Metadata URL: https://app.refrax.onl/auth/saml/metadata
Okta
- In Okta Admin, go to Applications → Create App Integration
- Select SAML 2.0, enter Refrax as the app name
- Single sign-on URL:
https://app.refrax.onl/auth/saml/acs - Audience URI:
https://app.refrax.onl/auth/saml/metadata - Add attribute statements:
email→ user.email,name→ user.displayName - Assign users/groups and copy the IdP metadata URL
- In Refrax Settings → Security, paste Entity ID, SSO URL, and x509 certificate
Azure AD (Entra ID)
- Azure Portal → Enterprise Applications → New application → Non-gallery
- Configure Single sign-on → SAML
- Identifier:
https://app.refrax.onl/auth/saml/metadata - Reply URL:
https://app.refrax.onl/auth/saml/acs - Download Federation Metadata XML or copy App Federation Metadata Url
- In Refrax Settings → Security, configure IdP details
- Verify your domain with DNS TXT record:
refrax-verify=<token>
Domain verification & enforce SSO
After configuring SAML, verify domain ownership in Settings → Security. Once verified, enable “Enforce SSO” to block password login for users with matching email domains.