Set up SSO and directory sync
Connect SAML single sign-on and SCIM directory sync so people, teams, and managers stay in step with your identity provider.
Single sign-on (SSO) lets people sign in to Tokenize through your identity provider. Directory sync (SCIM) then keeps your user list, teams, and reporting lines up to date, and cuts off access when someone leaves. Tokenize works with any identity provider that supports SAML SSO and SCIM 2.0 provisioning.
Who can do this: Admins.
Before you start
Set up SSO first. Directory sync runs on top of your SSO connection, so the Sync users button stays disabled until a connection exists.
Set up SSO
- Go to Settings → Directory Sync and click Set up SSO. This opens Settings → Organization.
- In Organization → SSO, add a SAML connection and verify your email domain.
- Return to Settings → Directory Sync. Your connection appears under SSO connections with its provider, domains, and an Active or Inactive status.
If you don't see the SSO option in your organization settings, contact your Tokenize account team to turn it on.
Set up directory sync
- After your SSO connection is in place, Tokenize enables directory sync and provides your SCIM URL and token. Contact your Tokenize account team if you haven't received them.
- Enter the URL and token in your identity provider's SCIM settings.
- Assign the users and groups that should appear in Tokenize.
- Map two custom attributes so Tokenize can build teams and reporting lines:
team, for example from the SCIM enterprisedepartmentattribute.manager_email, the email address of each person's manager.
- Assigned users appear in the Directory users table as your identity provider sends updates.
The Synced fields column under SSO connections shows Mapped or Not mapped for Team and Manager email. If either says Not mapped, check the attribute mapping in your identity provider.
Teams and managers drive team budgets and the views managers see for their reports. See Roles and permissions and Budgets.
Check sync status
The top of Settings → Directory Sync shows:
| Stat | What it means |
|---|---|
| Directory users | Everyone Tokenize knows about in your directory. |
| Synced from directory | People provisioned through SCIM. |
| Deactivated | People deactivated in your identity provider. |
| Last synced | When Tokenize last received or pulled directory data. |
In the Directory users table, Source shows Directory sync for SCIM-provisioned people and Manual for people added another way. The table lists the most recently updated people.
Your identity provider sends updates on its own. To pull the latest directory data right away, click Sync users. Tokenize confirms with a message such as "12 users synced."
When someone leaves
Deactivate the person in your identity provider. Tokenize then blocks their sign-in and revokes their device keys, so their computers stop sending data. Reactivating the person does not restore those keys; they need to set up their devices again. See Delete your data for removing people and their data.
Troubleshooting
- "Couldn't load directory sync. Try again." Click Retry. If it keeps failing, contact your Tokenize account team.
- "Couldn't sync users. Try again." Confirm your SSO connection is Active, then try Sync users again.
- "No users synced yet. Assign users in your identity provider to start syncing." Assign users or groups to the Tokenize app in your identity provider.
- "User counts and the directory list are unavailable." The directory list can't be shown right now. Deactivating users in your identity provider still revokes their device keys.
- "You don't have access to manage directory sync." Ask an admin to do this.