# SSO for 3D printer management: SAML & OpenID Connect (OIDC)

**Minimum Plan:** Enterprise

Single sign-on for SimplyPrint with SAML 2.0 and OpenID Connect. One-click setup for Entra ID, Google Workspace, Okta, Keycloak and Auth0, plus SCIM.

**Categories:** organization

*One login for your whole account*

## Single sign-on with the identity provider you already run

Let people sign in to SimplyPrint with the account they already have - their Microsoft, Google, Okta or any standards-compliant login. SimplyPrint speaks both **SAML 2.0** and **OpenID Connect (OIDC)**, so your admin connects your identity provider once and everyone signs in with their existing work or school account. No extra password to remember, no separate user list to keep in step by hand.

## Built for IT, schools and print farms with real user directories

Whether you run a school district on Google Workspace, a company on Microsoft Entra ID, or a print farm with a mixed team, SimplyPrint connects to your directory so the right people get in, the right way, with no shared logins and no manual account juggling.

## Works with the identity providers you already use

Connect your provider once in account settings. OpenID Connect has one-click presets for the major providers, SAML 2.0 covers everything else, and a generic option handles any standards-compliant identity provider.

## OpenID Connect (OIDC) with one-click presets

OpenID Connect is the quickest way to connect. Choose a preset for **Microsoft Entra ID**, **Google Workspace**, **Okta**, **Keycloak** or **Authentik** and SimplyPrint pre-fills the scopes and claim mappings for you - or pick the generic option for any standards-compliant OIDC provider. Copy the redirect URI we show into your provider, paste your client ID and secret back, and the setup wizard checks your discovery document live before you save.**
Under the hood it uses the OIDC authorization-code flow with PKCE**, validates every signed ID token (RS256 or stronger, never an unsigned or HMAC token), checks the nonce, and pins the issuer and audience to your provider. When your provider supports single logout, signing out of SimplyPrint signs the user out at the provider too.

## SAML 2.0 for any enterprise identity provider

Need SAML? SimplyPrint is a full SAML 2.0 service provider. Presets for **Google Workspace**, **Microsoft Entra ID** and **Auth0** auto-fill the endpoints, and a generic option connects any SAML 2.0 identity provider. Signed assertions are required by default, and you get the SP entity ID, ACS URL and metadata URL right in the setup screen to paste into your IdP.**
For research and education, SimplyPrint also supports SAML federation** sign-in so members of a federation can connect through their existing federated login.

## Verify your domain and route people to the right login

Add a DNS TXT record to prove you own a domain like *yourschool.edu* or *yourcompany.com*. Once a domain is verified, anyone who types a work or school email at that domain is sent straight to your single sign-on - no need to find the right button first. Verified domains also let SimplyPrint trust new accounts created on first sign-in, so the right people land in the right account automatically.

## Accounts that create and clean up themselves

Stop maintaining a second copy of your user list by hand. SimplyPrint can create accounts the first time someone signs in (just-in-time provisioning), and connect to **SCIM 2.0** so your identity provider pushes the full picture: new people get an account, and people who leave are removed automatically. Live SCIM guides cover Okta and Microsoft Entra ID.

### Just-in-time sign-up

First sign-in creates the account, gated by trusted email.

### SCIM provisioning

Your directory adds and removes people automatically.

### No orphaned logins

Deprovisioning removes access when someone leaves.

## Map your groups to roles, and lock down who gets in

Send a group or attribute from your identity provider and SimplyPrint maps it to the right SimplyPrint user group, so people arrive with the correct role and permissions instead of being set up one by one. You can also add a sign-in rule that only lets people in when a chosen attribute or claim matches a value you set - useful for restricting access to a specific department, staff group or class.

## SSO, tuned to how you run your printers

Single sign-on means something different for a school district than it does for a company. Start with the guide built for you.

## Frequently asked questions

### Do you support SAML, OIDC, or both?

Both. SimplyPrint is a full SAML 2.0 service provider and an OpenID Connect relying party. Your admin picks whichever your identity provider uses and configures it once per account. OIDC is usually the fastest to set up thanks to the one-click presets; SAML covers enterprise and federated logins.

### Which identity providers can I connect?

OpenID Connect has one-click presets for Microsoft Entra ID, Google Workspace, Okta, Keycloak and Authentik, plus a generic option for any standards-compliant OIDC provider. SAML has presets for Google Workspace, Microsoft Entra ID and Auth0, plus a generic option for any SAML 2.0 identity provider and SAML federation sign-in.

### Are accounts created automatically when people sign in?

They can be. With just-in-time provisioning, the first sign-in creates the account - gated by a trusted email rule so only the right people are auto-created. For full control, connect SCIM 2.0 so your identity provider pushes new people in and removes people who leave, with no manual list to maintain.

### How are roles and permissions assigned through SSO?

Map a group or attribute from your identity provider to a SimplyPrint user group. People then arrive with the correct role and permissions automatically. You can also add a sign-in rule that only lets people in when a chosen attribute or claim matches a value you set.

### What is a verified domain and why would I add one?

You verify a domain you own (for example yourcompany.com) by adding a DNS TXT record. Once verified, anyone typing an email at that domain is routed straight to your single sign-on, and SimplyPrint can trust accounts created on first sign-in for that domain. It removes the guesswork of finding the right login button.

### Is single sign-on secure?

Yes. OIDC uses the authorization-code flow with PKCE, validates signed ID tokens (RS256 or stronger, never unsigned or HMAC tokens), checks the nonce, and pins the issuer and audience to your provider. SAML requires signed assertions by default. SimplyPrint is built in the EU and is GDPR compliant.

### Which plans include single sign-on?

SSO is included on the School and Enterprise plans, with everything (SAML, OIDC, SCIM, verified domains and group mapping) part of the plan rather than a separate add-on. Print Farm subscribers from before the Enterprise plan launched keep their SSO access.


---

**Learn more:** [Help Article](https://help.simplyprint.io/en/article/set-up-openid-connect-oidc-single-sign-on-for-simplyprint-1bypz64/)
