What is SSO/SAML?
SSO, which stands for Single Sign On, is a convenient way of logging into multiple services or platforms using just one set of credentials. Instead of remembering a different username and password for every website or app you use, you just use one combination to access them all. SAML is the technology behind the scenes that makes this seamless process possible. Think of it like having a universal key that opens multiple locks, ensuring that your access is both simple and secure.SSO controls who can sign in to the Scribe dashboard. It does not import employee data into your signatures. To pull job titles, departments or phone numbers from your identity provider, connect it as a Smart Fields data source as well — see the Okta integration, for example.
Before you start
You will need:- A paid Scribe subscription. The SSO add-on cannot be purchased on its own.
- The Single Sign-On add-on: 120 per month billed yearly. Available on any paid plan.
- The Owner or Admin role in your Scribe workspace.
- Access to your domain’s DNS settings (to verify domain ownership).
- Admin access to your identity provider — Okta, Microsoft Entra ID, Google Workspace, OneLogin, or any SAML/OIDC-compatible IdP.
Activate the add-on
1
Open the Single Sign-On settings
In your Scribe dashboard, go to Settings → Security → Single Sign-On.
2
Add SSO to your subscription
Click Subscribe for $150/month and confirm. The add-on is applied to your existing subscription immediately.If you are still on a free plan or a trial, Scribe will prompt you to choose a paid plan first.
Configure SSO
Once the add-on is active, Scribe walks you through a three-step setup.1
Add your sign-in domain
Enter the email domain your team signs in with — for example
your-company.com — and click Continue.This is the domain Scribe matches against when someone types their email on the login page. Use the domain in your teammates’ email addresses, not a subdomain.2
Verify your domain
Click Start verification. Scribe opens a guided wizard that adds the required
TXT record to your DNS automatically for most providers — no developer or manual DNS editing needed.If your provider isn’t supported by the wizard, it shows you the exact record to add by hand.The domain’s status is shown as a badge in the domains table:DNS propagation is usually quick, but it can take up to 24 hours. Scribe moves you to the next step automatically once the domain is verified.
3
Connect your identity provider
Click Configure SSO. You are redirected to a secure setup portal where you pick your identity provider — Okta, Microsoft Entra ID, Google Workspace, OneLogin, or a generic SAML/OIDC connection — and follow the provider-specific instructions.The portal tells you exactly which values to copy into your IdP (such as the ACS URL and Entity ID for SAML) and which values to copy back.When you’re done, you are returned to Settings → Security → Single Sign-On in Scribe. SSO becomes active as soon as your identity provider marks the connection as active.
How your team signs in afterwards
On the login page, a teammate types their email address. If the domain matches a verified SSO domain and your connection is active, Scribe shows Single sign-on detected and replaces the password field with a Log-in with SSO button. Clicking it sends them to your identity provider to authenticate.Teammates whose email domain is not covered by an SSO domain keep signing in as before — with email and password, Google, or Microsoft 365.
Managing your domains
Once SSO is configured, Settings → Security → Single Sign-On lists every sign-in domain with its verification status.- Add a domain — click Add Domain to cover an additional email domain (useful after a rebrand or an acquisition). Each new domain has to be verified the same way.
- Delete a domain — click the bin icon. You cannot delete your last remaining domain.
If you cancel the add-on
Removing the SSO add-on — or cancelling your subscription — deletes the SSO connection and deactivates SSO for your workspace. Your teammates fall back to email and password, Google, or Microsoft 365 sign-in. Your domains stay listed, so re-subscribing only requires reconnecting your identity provider.Related articles
- How do I configure 2FA in Scribe?
- Okta Smart Fields: sync job titles and other profile data from Okta into your signatures.
- Members
- What Scribe does concerning security