With single logout (SLO), users can log out from the identity
provider and the service provider by logging out from either of them. Whether Salesforce
is the service provider or identity provider, you can enable SLO with SAML or OpenID
Connect. SLO can increase security and save users time by removing manual logout from
every individual application.
Required Editions
Available in: both Salesforce Classic and Lightning
Experience
User Permissions
Needed
To view the settings:
View Setup and Configuration
To edit the settings:
Customize Application
AND
Modify All Data
Important Connected apps creation is restricted as of Spring ‘26. You can continue
to use existing connected apps during and after Spring ‘26. However, we recommend using external client apps instead. If you must continue
creating connected apps, contact Salesforce Support.
SLO can be initiated from either the service provider or identity provider. For example,
if Salesforce is the identity provider, users can log out from Salesforce to
automatically log out of service providers using single sign-on (SSO). Alternatively,
users can log out from a service provider to also log out of Salesforce.
To use SLO, identity providers and service providers must be configured for SSO and
registered for SLO.
Salesforce currently supports front-channel SLO only, meaning that
SLO redirects must occur in the same browser. Salesforce doesn’t support SLO across
different browsers. Your users are only logged out of their registered apps if they
explicitly log out of an external client app or connected app through a browser. If a browser
session expires, users aren’t logged out of the other apps registered for SLO.
Salesforce supports these protocols.
SAML SLO as an identity provider or service provider
OpenID Connect SLO as an identity provider or relying party
SAML Session Index Support Salesforce supports session index parameters in requests and responses with SAML single logout (SLO). When a user logs out of a connected app registered for SAML SLO, the session index parameter is required to identify which user session to end.
Did this article solve your issue?
Let us know so we can improve!
Loading
Salesforce Help | Article
Cookie Consent Manager
Cookie Consent Manager
General Information
Required Cookies
Functional Cookies
Advertising Cookies
General Information
We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required Cookies
Always Active
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional Cookies
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising Cookies
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.