Go to MarketplaceHub

Single sign-on with your identity provider

Let your team sign in with Microsoft Entra ID, Okta, Google Workspace or any OpenID Connect or SAML 2.0 provider: create the connection, verify your domains, test it, and optionally require it.

What single sign-on does

Single sign-on (SSO) lets your team sign in to MarketplaceHub with the work account they already have at your company's identity provider — Microsoft Entra ID, Okta, Google Workspace or any provider that speaks OpenID Connect or SAML 2.0. Your identity provider checks who they are; MarketplaceHub then signs them in as a member of your account, with the access you gave them.

Only administrators can set it up: user menu → Security → Single sign-on → Set up single sign-on.

Before you start

  • You need administrator rights in your identity provider, to create an app there.
  • You need to be able to add a DNS TXT record to each email domain your team uses (for example acme.com). This is how we know the domain is yours.
  • Public mailbox domains such as gmail.com or outlook.com can't be used — nobody owns them.

Step 1 — Create the connection

Give the connection a Name (your team sees it only in settings) and choose a protocol. Both work the same way for your team; pick the one your identity provider makes easiest.

OpenID Connect

  1. In your identity provider, create a web application and set its redirect URI to the Redirect URI MarketplaceHub shows you. Copy it exactly.
  2. Allow the openid, profile and email scopes. The person's email address must be in the sign-in.
  3. Back in MarketplaceHub, paste the Issuer URL, Client ID and Client secret, and click Create connection. The secret is stored encrypted and is never shown again.

SAML 2.0

  1. MarketplaceHub shows two values for your identity provider: the Identifier (Entity ID) — our metadata URL — and the Reply URL (Assertion Consumer Service).
  2. In your identity provider, create a SAML application with those two values. It must sign the assertion or the response, send a persistent NameID or the email address, and send the person's email as an attribute.
  3. Paste your identity provider's metadata XML into MarketplaceHub — it fills in the entity ID, the sign-in URL and the signing certificate for you — and click Create SAML connection. If you prefer, fill those three fields in by hand.

When your provider rolls to a new signing certificate, paste both the old and the new one. Each stored certificate is listed with its expiry date, and one that expires soon is marked.

Notes for common providers

Microsoft Entra ID

  • OpenID Connect: create an App registration with a Web redirect URI. The issuer URL is https://login.microsoftonline.com/<your tenant ID>/v2.0 — use your own tenant ID, not common or organizations, which we refuse because they would accept anyone's Microsoft account. Create a client secret under Certificates & secrets, and add the email optional claim to the ID token under Token configuration.
  • SAML: create an Enterprise application (your own, non-gallery), choose SAML, enter the Identifier and Reply URL, then paste the Federation Metadata XML.

Okta

  • OpenID Connect: create an app integration of type OIDC — Web Application, with the Redirect URI as its sign-in redirect URI. The issuer URL is your Okta domain, for example https://acme.okta.com.
  • SAML: create a SAML 2.0 app integration. The Reply URL is Okta's Single sign-on URL, and the Identifier is its Audience URI (SP Entity ID). Set the Name ID format to EmailAddress, add an email attribute statement, then paste the app's metadata.

Google Workspace

  • Use SAML: in the Admin console, go to Apps → Web and mobile apps → Add custom SAML app. Download the IdP metadata, enter the Reply URL as the ACS URL and the Identifier as the Entity ID, set the Name ID to the primary email, and turn the app on for the people who need it.

Step 2 — Verify your email domains

Under Email domains, click Add domain. MarketplaceHub shows a TXT record that starts with mh-sso-verification=. Add it to the domain's DNS, then click Verify. DNS changes can take a while to spread; if it isn't found yet, try again later.

A verified domain is what sends people to your identity provider, and it is the only way an email address can link someone the first time they sign in. A domain can belong to one MarketplaceHub account only.

Step 3 — Test, then turn it on

  1. Click Start testing. While a connection is Testing, nobody else is affected.
  2. Click Test sign-in and sign in with your own work account at the identity provider. You stay signed in to MarketplaceHub as yourself — the test only proves the connection works.
  3. When the page says the test sign-in worked, click Turn on. Your team can now use it.

Changing the issuer, client ID or secret — or, for SAML, the entity ID, sign-in URL or certificates — puts the connection back into testing until a test sign-in works again.

How your team signs in

On the sign-in page, a team member clicks Sign in with company SSO and enters their work email. MarketplaceHub sends them to your identity provider, and back again once they're in.

  • Existing team members are linked the first time they sign in, by their email address on a verified domain. After that, the link is to their account at your identity provider, not to the email.
  • New people: under Options, you can create a team member automatically the first time someone from your domains signs in, with the access you choose. Otherwise, invite them from Team & roles first.
  • If you allowed it, people can also start from your identity provider's own app portal (SAML only).

Requiring single sign-on

Under Options, tick Require single sign-on for team members. From then on, a team member can't sign in with a password, a passkey, or a Google or Amazon account — the sign-in page sends them to your identity provider instead. People can't create a new MarketplaceHub account with a password on your domains, either.

You, the account owner, always keep your own sign-in. The owner is never signed in through single sign-on, so a problem with your identity provider can never lock you out of your account.

Sessions and removing access

  • Sign-in lasts at most a set number of hours — 12 unless you change it, and no more than 168 (one week). After that, the person signs in through your identity provider again. So someone you remove there loses access within this time. A new limit applies to new sign-ins.
  • Some changes end sign-ins at once: turning the connection off, deleting it, and changing its sign-in settings end everyone's single sign-on sessions. Removing a verified domain ends the sessions of the people on that domain.
  • To remove someone straight away, remove them from Team & roles as well as from your identity provider.

If sign-in doesn't work

  • "Your company's sign-in could not be verified" — usually a certificate or setting mismatch. Check the certificates and the Identifier and Reply URL in your identity provider, then run Test sign-in again.
  • "Your identity provider sends a different ID every time" — change the SAML Name ID to persistent or to the email address.
  • "Start your sign-in from the MarketplaceHub sign-in page" — sign-in started from the provider's portal is off. Turn it on under the connection's settings, or start from our sign-in page.
  • The sign-in took too long — start again from the sign-in page; a sign-in must finish within a few minutes.
We answer real mail

Still stuck? We're here.

Tell us what you were doing and what happened — the notification text or a product SKU helps us find it fast.