With SAML single sign-on (SSO), your team signs in to redirect.pizza through your own identity provider (IdP), such as Okta, Microsoft Entra ID or Google Workspace. This article covers the configuration on both sides. Available from the Business plan and up.
Using Okta? Follow the dedicated SSO via Okta guide, which uses our integration from the Okta Integration Network.
Setting up
Open More, SAML SSO in redirect.pizza. You'll find your Entity ID, ACS URL, SLS URL and signing certificate links there.
In your identity provider, create a new SAML application with the Entity ID and ACS URL from that page, and set the following options where available:
- Name ID format: EmailAddress
- Signed assertions: yes
- Encryption: preferred. Download our current certificate.
Uploading your IdP metadata
Download the metadata XML file from your identity provider and upload it on the SAML SSO page. We extract the details we need automatically. By default the connection is set up for a single email domain. If you need multiple domains, or a different one than detected, support can adjust it.
As soon as the metadata is uploaded, SAML SSO is active.
Signing in
Users can sign in through your IdP (IdP-initiated) or from the redirect.pizza sign-in page. When someone enters an email address on a domain with SSO configured, we offer to sign them in with SAML SSO directly.

Access
SSO authenticates users; it doesn't grant access by itself. Only users who have been invited to your team in redirect.pizza can sign in. Invite them under More, Users. They receive a one-click link that activates their account with SSO.
Single logout
redirect.pizza supports SAML Single Logout (SLO), so users can be signed out through your IdP. Configure the SLS URL from the SAML SSO page in your identity provider to enable IdP-initiated logout.
Certificate rotation
redirect.pizza renews its SAML signing certificate automatically. When a new certificate is issued, both the current and the expiring certificate stay valid for about 60 days, so you have time to update your identity provider.
During that window you receive an email, and the SAML SSO page links to both certificates:
- Current certificate: add this to your IdP.
- Expiring certificate: keep this in your IdP until the cutoff date in the email.
The easiest option is to re-import our SP metadata from the metadata URL on the SAML SSO page. That picks up both certificates for you.
After the cutoff, only the current certificate remains valid. If your IdP still has only the old one, SAML sign-in stops working until you update it.