Loading

Configure Salesforce as an Identity Provider for Quip SSO

Udgivelsesdato: Aug 18, 2026
Beskrivelse

This article explains how to configure Salesforce as a Security Assertion Markup Language (SAML) identity provider (IdP) for Quip single sign-on (SSO). With this configuration, users log in to Quip using their Salesforce credentials, eliminating the need for a separate Quip password. Use this guide when setting up Quip SSO for the first time through Salesforce or when troubleshooting an existing configuration.

Løsning

Prerequisites

  • Salesforce administrator access with permission to create connected apps
  • Quip site administrator access to the Quip Admin Console
  • Quip Plus or Quip Advanced subscription (SSO is not available on basic Quip plans)

Step 1: Configure Salesforce as a SAML Identity Provider

  1. In Salesforce Setup, search for Identity Provider in the Quick Find box.
  2. Click Enable Identity Provider and save. Salesforce generates a self-signed certificate.
  3. Download the identity provider metadata by clicking Download Metadata. You will upload this file to Quip in Step 3.

Example: A company standardizing all SaaS application logins through Salesforce configures Salesforce as the IdP so that field sales reps can open Quip from the Salesforce app navigation and be automatically authenticated without a separate login prompt.

Step 2: Create a Connected App in Salesforce for Quip

  1. In Salesforce Setup, go to App Manager and click New Connected App.
  2. In the Web App Settings section, enable Enable SAML.
  3. Set the Entity ID to your Quip site URL: https://[yoursite].quip.com
  4. Set the ACS URL (Assertion Consumer Service URL) to: https://[yoursite].quip.com/saml/login
  5. Set the Subject Type to Username or Federation ID depending on how your user emails map between Salesforce and Quip.
  6. Save the connected app.

Step 3: Upload Salesforce Metadata to Quip

  1. In the Quip Admin Console, navigate to Settings > Accounts & Access.
  2. Click New Configuration.
  3. Upload the Salesforce IdP metadata XML file you downloaded in Step 1.
  4. Enter a test email address and click Test Configuration to verify the setup before enabling it for all users.
  5. Once the test is successful, click Enable for Entire Company.

IdP-Initiated vs. SP-Initiated Login

Quip supports both SSO flows:

  • IdP-initiated: The user opens Quip from a tile in the Salesforce app launcher or from an App Launcher shortcut. Salesforce sends a SAML assertion directly to Quip.
  • SP-initiated: The user navigates to your Quip site URL. Quip redirects the user to Salesforce for authentication, then returns them to Quip after a successful login.

Single Identity Provider Limitation

Quip supports only one active SAML configuration at a time. If your organization uses multiple identity providers, you must configure one unified IdP for Quip or use a federation service that aggregates multiple IdPs into a single SAML endpoint.

Updating the SAML Certificate

Salesforce certificates expire and must be renewed periodically. When your Salesforce certificate expires, SSO breaks for all Quip users until the certificate is updated. See How to Add/Update a New SAML Certificate for Quip for renewal steps.

Vidensartikelnummer

000392629

 
Indlæser
Salesforce Help | Article