redirect.pizza can connect directly with your IdP to enable SSO via SAML2. This guide provides the necessary information for configuration.
Note: SAML SSO is available from our Business plan and up.
Setting up
Open SAML SSO in redirect.pizza. You'll find your Entity ID, ACS URL, SLS URL, and signing certificate links there.
Navigate to your identity provider and set-up your SSO connection with the Entity ID & ACS URL as defined here.
Set the following options if available:
- Name ID format: EmailAddress
- Signed Assertions: Yes
- Encryption: Preferred. Download our current certificate.
Uploading the metadata XML file
Download your IdP's metadata XML file and upload it under the same segment. We'll extract the necessary details automatically. By default, the integration is set up for a single domain. If you need multiple domains (or another one than set by default), support can assist.
Once the metadata XML is uploaded, the SAML SSO connection becomes active.
Authentication
When SAML SSO is activated, users may authenticate through their IdP or via redirect.pizza. When a domain is detected in the email address, we'll prompt the user with the ability to login directly with SAML SSO.

Access
Only users that have been invited via redirect.pizza may access the account.
You can invite new users under More -> Users. They will receive an one-click link which can be used with SSO to activate their account.
Single logout
redirect.pizza supports SAML Single Logout (SLO), allowing users to be logged out via your IdP. The SLO URL can be found in your SAML settings under More -> Settings. Use this URL in your identity provider to configure IdP-initiated logout.
Certificate rotation
redirect.pizza automatically renews its SAML signing certificate. When a new certificate is issued, both the current and expiring certificates stay valid for about 60 days so you have time to update your Identity Provider.
During that window you'll get an email, and the SAML SSO page shows links to both certificates:
- Current certificate: add this to your IdP
- Expiring certificate: keep this in your IdP until the cutoff date in the email
The easiest option is to re-import your SP metadata from the metadata URL on the SAML SSO page. That picks up both certificates for you.
After the cutoff, only the current certificate remains valid. If your IdP still has only the old one, SAML sign-in will stop working until you update it.
