Single sign-on (SSO)
Your team signs in through your company's identity provider instead of an emailed code. Sellio supports OpenID Connect (Okta, Microsoft Entra ID, Google Workspace) and SAML 2.0.
Before you start
- Single sign-on is part of the Enterprise plan. Other plans see a Contact us card under Settings, then Security.
- Only the owner and admins can set it up (only the owner, while the owner has restricted settings).
- You need access to your domain's DNS, to add one TXT record, and to an admin console of your identity provider.
1. Verify your domain
- 1Settings, then Security. Under Domains, type the domain your team's addresses use, such as acme.com, and select Add domain.
- 2At your DNS provider, add the TXT record the page shows: the name is
_sellio-verify.acme.comand the value issellio-verify=followed by your token. Copy both from the page. - 3Back in Sellio, select Verify. DNS changes usually show up within minutes, sometimes longer; you can try again as often as you need.
ℹ
Public email domains such as gmail.com or outlook.com cannot be added. Once a workspace has verified a domain, no other workspace can add or verify it. A subdomain such as eu.acme.com is a domain of its own and needs its own record.
2. Add a connection
- 1Under Connections, select Add connection and pick OpenID Connect (OIDC) or SAML 2.0.
- 2Copy the values under Give your identity provider these into a new app in your identity provider: the Redirect URI for OIDC; the ACS URL and Entity ID for SAML (the Metadata URL appears once the connection is saved).
- 3Paste what the identity provider gives back: the issuer URL, client ID and client secret for OIDC; the metadata XML (or the sign-in URL, entity ID and signing certificate) for SAML.
- 4Tick the verified domains this connection covers, and save.
The client secret is stored and never shown again. To change it, type a new one; leave the field blank to keep the saved one.
Provider notes
Okta (OIDC)
Applications, then Create App Integration, OIDC, Web Application. Add the Redirect URI as a sign-in redirect URI, keep Authorization Code, and assign the people or groups who should get in. The issuer is your Okta address, such as
https://acme.okta.com.Microsoft Entra ID (OIDC)
App registrations, then New registration, with the Redirect URI as a Web redirect URI. Create a client secret under Certificates & secrets, and under Token configuration add the optional
email claim to the ID token. The issuer is https://login.microsoftonline.com/{tenant-id}/v2.0 with your directory (tenant) ID.Google Workspace (OIDC)
In Google Cloud, create an OAuth client of type Web application with the Redirect URI, on a consent screen set to Internal. The issuer is
https://accounts.google.com.Any SAML 2.0 provider
Use the ACS URL as the single sign-on (reply) URL and the Entity ID as the audience. Send the person’s email as the NameID in email format, or as an attribute named
email, and sign the assertion or the response with SHA-256. Paste the provider’s metadata XML into Sellio.3. Test and turn it on
- 1Select Test sign-in on the connection (it appears once the connection is set up and covers a domain). It works while the connection is off, for the owner and admins only, and brings you back to the Security page with the result.
- 2When the test works, switch the connection on. From then on anyone with an address on its domains can use it.
How your team signs in
- On the sign-in page, Continue with SSO asks for a work email. Sellio finds the connection from the domain and sends the person to your identity provider.
- Someone signing in for the first time gets a Sellio account and joins your workspace as a member (agent role); admins can change the role afterwards. A free seat is needed, as for an invitation.
- Someone who already has a Sellio account with the same address keeps it: the connection is added to that account.
- The desktop apps do not offer SSO; sign in at sellio.chat in the browser, or with an email code in the app.
⚠
Removing someone in Sellio does not stop them from signing in again through the connection while your identity provider still lets them in: remove or unassign them in the identity provider first.
Rules and limits
- The address your identity provider returns must be on one of the connection's verified domains, exactly; anything else is refused.
- SAML responses must be signed with SHA-256 or stronger, and must answer a sign-in that started on Sellio. Sign-ins started from the identity provider's own dashboard are not accepted.
- OpenID Connect sign-ins use PKCE, and Sellio checks the ID token's signature, audience and issuer.
- A workspace can have up to 20 domains and 5 connections. A domain belongs to one connection.
- Every change to domains and connections is recorded under Settings, then Logs, unless the owner has switched logging off.
Roles and the rest of sign-in are covered in Team and permissions.
Updated . Something wrong or missing? Tell us.