Skip to main content

SSO Integration

Written by Tim Cameron

Sine’s SAML 2.0 SSO solution allows your company to have @yourcompany.com users provisioned and logged into Sine via your chosen identity provider (IdP). This login, initiated from Sine or your IdP, will take the user to their Sine account without the need for a Username/Password.

Please note:

  • Provisioning of account access to sensitive company data is granted separately — utilising our Hosts setup (guide here) and through manual admin team provisioning (guide here)

  • This is a fully managed service and requires a medium, large or enterprise plan.

  • This configuration can only be requested by someone with Team Administrator access to their organisations Sine account.

Provisioning

For provisioning, your company SSO administrator will need access to the settings of the Company's chosen IdP (e.g. Entra ID).

Sine will confirm your preferences for the following settings:

  • Company name listing (e.g. "Sine Group Pty Ltd")

  • Preferred session timeout (e.g. "8 hours"). This controls how often users have to re-authenticate.

  • Domain(s) to be included (e.g. "sine.co"). Multiple domains can be listed at this point, or added in the configuration later.

These are the assertions we expect to be sent from your company's IdP:

  • givenName OR http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname (First name)

  • sn OR http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname (Last name)

Note: The latter are the default assertions sent by Entra ID, so no changes are required if using that as your IdP.
We also expect the NameID format to be urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress and contain the user's email address. If you'd like to use something other than the email address as the NameID, this will need to be discussed.
Once you have this information, please contact us and your request will be escalated to our technical team.

Frequently Asked Questions:

How do I use SSO to log into Sine?
Sine’s SSO solution can be either SP or IdP initiated. SP initiated means you can enter your corporate email into the Sine login page and you will be redirected to your IdP provider's SSO page. This is the most common option. IdP initiated means you must first login to your IdP provider's SSO page and then click on/locate Sine from the list of available apps to access.

Are users automatically provisioned by the SSO integration?
Yes, user provisioning is also handled by the SSO solution. When a user tries to log in from the IdP and Sine does not recognise the source email address, a new user will be created and the user will be logged in.

Provisioning of account access to sensitive company data is granted separately — utilising our Hosts setup (guide here) and through manual admin team provisioning (guide here)

Can users be provisioned as Hosts using the SSO integration?
No, the provisioning of hosts to your site(s) needs to be actioned by an Admin (Collaborator) from within the Sine Dashboard. More detail on adding hosts here

Can users be provisioned as Collaborators (Admins) using the SSO integration?
No, the provisioning of access to sensitive company data must be actioned by an existing Admin (Collaborator) from within the Sine Dashboard. More detail on team set up here

Did this answer your question?