Configure SSO from Salesforce to Dropbox
Let your users log in to Dropbox using single sign-on (SSO) from your Salesforce org configured as an identity provider.
Required Editions
| Available in: Lightning Experience and Salesforce Classic |
| Available in: Enterprise, Performance, Unlimited, and Developer Editions |
When you set up Dropbox as a service provider and create a connected app, users can access Dropbox using their Salesforce login credentials. Dropbox supports the SAML protocol for both identity provider–initiated and service provider–initiated SSO.
Follow these high-level steps to configure SSO for Salesforce to Dropbox.
Set Up Your Salesforce Org as an Identity Provider
With the My Domain feature, your Salesforce org is enabled as an identity provider. My Domain is required for all orgs. If you don’t like your org’s My Domain name, you can change it.
The My Domain feature also creates a certificate and key pair. The certificate establishes trust between your Salesforce org and ADP. Optionally, you can use another self-signed certificate or import a CA-signed certificate.
To download the Salesforce self-signed certificate:
- From Setup, enter Identity Provider in the Quick Find box, and select Identity Provider.
- Click Download Certificate.
Configure SAML Settings in Dropbox
- Log in to your Dropbox account as an administrator.
- Click Admin Console.
- Click Settings.
- Under Authentication settings, click Single sign-on.
- Choose whether SSO is optional or required.

- Dropbox displays information about SSO setup, including a URL for service provider–initiated SSO, for example, https://www.dropbox.com/sso/11272027. Save this URL to use later when you test the configuration.
- For Identity provider sign-in URL, enter the HttpRedirect endpoint, for example, https://MyDomainName.my.salesforce.com/idp/endpoint/HttpRedirect. For example, https://identity.my.salesforce.com/idp/endpoint/HttpRedirect.
- Optionally, for Identity provider sign-out URL, enter the URL to which the user is redirected after logout.
- For X.509 certificate, upload your Salesforce certificate.
- Save the settings.
Create a Connected App in Salesforce
- In Salesforce, create a connected app.
- In Lightning Experience, from Setup, enter App in the Quick Find box, and select App Manager. Click New Connected App.
- In Salesforce Classic, from Setup, enter Apps in the Quick Find box, and select Apps. Under Connected Apps, click New.
- Configure the connected app Basic Information settings.
- Enter a name for the Dropbox connected app. Salesforce uses this name to populate the API name.
- Enter your email address in case Salesforce needs to contact you or your support team.
- Optionally, upload or specify a logo and icon to represent your Dropbox application
in the Salesforce App Launcher.

- Configure the connected app Web App Settings.
- Select Enable SAML.
- For Entity Id, enter Dropbox.
- For ACS URL, enter https://www.dropbox.com/saml_login.
- For Subject Type, select how a user in Dropbox maps to a Salesforce user identity, for example, Federation ID. A federation ID is a unique value assigned to a user across multiple web services and Salesforce orgs.
- For Name ID Format, keep the default value.
- For Issuer, keep the default value, which is your My Domain login URL.
- For IdP Certificate, keep the default (Default IdP Certificate).
- Save the settings.

- Configure profiles and permission sets for the connected app.
- From Setup, enter Apps in the Quick Find box.
- If you’re using Lightning Experience, select Manage Connected Apps.
- If you’re using Salesforce Classic, under Manage Apps, select Connected Apps.
- Click the name of your connected app for Dropbox. The connected app detail page appears.
- Click Manage Profiles or Manage Permission Sets, and add profiles or permission sets for the users who can access this app.
- From Setup, enter Apps in the Quick Find box.
- In Salesforce, enter the start URL for the connected app.
- On the connected app detail page, under SAML Login Information, copy the IdP-initiated login URL.
- On the connected app detail page, click Edit Policies.
- For Start URL, paste the IdP-initiated login URL.
- Save the settings.
Test the SSO Configuration
- In Salesforce, from the App Launcher, find and open the Dropbox
app. If you configured the Dropbox logo and icon for the connected app, the App Launcher
displays them. If identity provider–initiated SSO is configured properly, Salesforce
creates an application session.

- To test service provider–initiated SSO, enter the URL that you saved when you configured SSO, for example, https://www.dropbox.com/sso/11272027. When you’re redirected to the Salesforce login page, enter your credentials. If SSO is successful, you’re logged in to your Dropbox account.

