Set up single sign-on (SSO) by using your Salesforce org or Experience Cloud site as a
SAML identity provider for an external service provider, such as Google Apps. In this SSO
configuration, users log in to the service provider with their Salesforce credentials. To set up
this configuration, enable Salesforce as an identity provider and integrate your service
provider using the external client apps framework or the connected apps framework.
Required Editions
Available in: both Salesforce Classic
and Lightning Experience
Available in: Developer, Enterprise, Performance,
Unlimited, and Database.com Editions
User Permissions
Needed
Define and modify identity providers and service providers:
Customize Application
Important Connected apps creation is restricted as of Spring ‘26. You can continue
to use existing connected apps during and after Spring ‘26. However, we recommend using external client apps instead. If you must continue
creating connected apps, contact Salesforce Support.
For example, you build a custom Your Benefits web app that implements SAML for user
authentication. You want your users to be able to log in to this app with their Salesforce
credentials. To set up this SSO flow, configure the Your Benefits web app as a Salesforce
external client app or connected app. Define your Salesforce org as the SAML identity provider
for the app. Your users can now log in to the Your Benefits web app with their Salesforce
credentials.
To set up this SSO configuration, follow these instructions.
Salesforce supports identity provider-initiated login and service provider-initiated login
for SAML. For service provider-initiated login, Salesforce supports forced authentication
requests. For more information about these login flows, see SAML SSO
Flows.
Steps, Examples, and More Information
See these links for information related to setting up SSO with Salesforce as a SAML
identity provider.
Enable Salesforce as a SAML Identity Provider You can configure Salesforce as a single sign-on (SSO) SAML identity provider to external service providers. When your org acts as a SAML identity provider, users can access multiple apps with a single login. To get started with this configuration, enable Salesforce as an identity provider and share configuration information with your service provider.
Integrate Service Providers as SAML-Enabled Apps To configure SAML single sign-on (SSO) with Salesforce as an identity provider, integrate a service provider by using the external client apps framework or the connected apps framework. With this SSO configuration, users log in to the service provider by using the same credentials that they use to log in to your Salesforce org or Experience Cloud site. To change your service provider details, edit your app. Control which users can access your app by managing profiles and permission sets.
Map Salesforce Users to the SAML Service Provider To ensure that your SAML service provider can recognize Salesforce users when they log in with single sign-on (SSO), update user information in Salesforce. Provide user identifiers that the service provider recognizes.
We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required Cookies
Always Active
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional Cookies
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising Cookies
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.