With Salesforce acting as the Service Provider in a SAML Single Sign-On (SSO) implementation, each Experience Cloud site uses its own unique set of login and logout endpoints. External users — including customers, partners, and community members — must authenticate using the endpoint that corresponds specifically to their Experience Cloud site.
When implementing SAML SSO for Experience Cloud, always use the site-specific Community endpoints for all external users. Directing users to the wrong endpoint prevents successful authentication and causes site access errors. All relevant XML elements in the SAML response — including the Destination attribute in the Response element and the Recipient attribute in SubjectConfirmationData — must contain the correct Experience Cloud site endpoint URL (e.g., https://<mydomainvalue>.my.site.com/login), not the internal org login URL.
How to Locate Experience Cloud SSO Endpoints
To access your SAML Single Sign-On endpoints, navigate to Setup → Single Sign-On Settings and review the settings as described in View and Edit Single Sign-On Settings.
To view your Community-specific endpoints, expand the For Experience Cloud dropdown below Your Organization on the Single Sign-On Settings page. Endpoints listed use your Site's Primary URL https://help.salesforce.com/s/articleView?id=sf.custom_url_add.htm&type=5.
Configuring SSO for Multiple Custom Domains
If your organization has multiple custom URLs serving a single Experience Cloud site, select the SSO option for each domain separately via Force.com. Navigate to All Sites → Workspaces → Administration → Pages → Go to Force.com → Login Settings for the non-primary custom URL and adjust the login options for that URL.
Employee Access to Experience Cloud Sites
If your site has the permission "Allow employees to log in directly to an Experience Cloud site" enabled under Login and Registration in Workspaces, employees must also be directed to the site-specific Experience Cloud endpoint for SSO. If this permission is not enabled, employees can access Experience Cloud sites through the App Launcher.
SAML Assertion Endpoint Requirements
In a valid SAML assertion targeting an Experience Cloud site, the following XML attributes must both point to the Experience Cloud site login URL — not the internal org login URL:
For example, both attributes must use the format: https://<mydomainvalue>.my.site.com/login
Verify that your Identity Provider is configured to populate these attributes with the correct Experience Cloud endpoint for each site before going live.
000395455

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.