SSO & SCIM
Configure SAML or OIDC single sign-on and SCIM provisioning with Okta, Microsoft Entra ID or Google Workspace, and map groups to Kimo roles and spaces.
Single sign-on lets your team log in with your identity provider, and SCIM keeps users and groups in sync automatically. Both are available on Business and Enterprise plans, and in every on-premise deployment. Read more about our approach on the security page.
Supported providers
| Provider | SSO | SCIM | Group sync |
|---|---|---|---|
| Okta | SAML 2.0, OIDC | Yes | Yes |
| Microsoft Entra ID | SAML 2.0, OIDC | Yes | Yes |
| Google Workspace | SAML 2.0 | Via directory sync | Yes |
| Keycloak | SAML 2.0, OIDC | Yes | Yes |
| Any SAML 2.0 IdP | SAML 2.0 | SCIM 2.0 | Yes |
Configure SAML
- 1Verify your domain
In Settings → Security → Domains, add a TXT record to prove you own
example.com. Only verified domains can enforce SSO. - 2Create an app in your IdP
Use the ACS URL and Entity ID shown in Kimo. Set the NameID format to email address.
- 3Upload IdP metadata
Paste the metadata URL or upload the XML. Kimo validates the certificate and shows its expiry date.
- 4Test, then enforce
Log in from a private window with Test SSO. Once it works, enable Require SSO; password logins are disabled except for break-glass admins.
ACS URL https://auth.getkimo.com/saml/acme/acsEntity ID https://auth.getkimo.com/saml/acmeNameID emailAddressAttributes email, firstName, lastName, groupsSCIM provisioning
Generate a SCIM token under Settings → Security → SCIM and paste it into your IdP with the base URL below. Users created in the IdP are provisioned on first assignment; deactivated users lose access within a minute and their sessions are revoked.
curl https://api.getkimo.com/scim/v2/Users?filter=userName%20eq%20%22ana@example.com%22 \ -H "Authorization: Bearer $KIMO_SCIM_TOKEN"Mapping groups to roles
| IdP group | Kimo role | Spaces |
|---|---|---|
kimo-admins | Admin | All |
finance | Editor | Finance |
growth | Editor | Growth, Web |
everyone | Viewer | Company |
Sessions and MFA
When SSO is enforced, session length and MFA are controlled by your identity provider. Kimo adds its own guardrails on top: sessions expire after 12 hours of inactivity by default (configurable from 1 to 72 hours), and sensitive actions such as creating API tokens, changing SSO settings or exporting more than 100,000 rows require a fresh login within the last 15 minutes.
- Restrict access to corporate networks with an IP allowlist (Enterprise).
- Every login, role change and token creation is written to the audit log and can be streamed to your SIEM.
- Break-glass logins trigger an email to all admins.
