SAML SSO
TeamsSAML Single Sign-On lets your team sign in to Lynkle using your organization's identity provider (IdP). Instead of managing separate passwords, team members authenticate through the same system they use for the rest of your company's tools.
Lynkle supports SAML 2.0 with any compliant identity provider. This guide covers the general setup process. For step-by-step instructions specific to your IdP, see:
Before you start
- A Lynkle Teams subscription
- Organization owner role in Lynkle
- Admin access to your identity provider (Azure AD, Google Workspace, Okta, or another SAML 2.0 provider)
- Access to your domain's DNS settings (for domain verification)
- Each SSO user invited to your Lynkle organization
How it works
Setting up SSO involves three steps, all managed from Settings > Security in your Lynkle dashboard.
- Connect your identity provider
Create a SAML application in your IdP and link it to Lynkle. Copy the Entity ID, SSO URL, and Signing Certificate from your IdP into Lynkle.
After saving, Lynkle displays three values to copy into your IdP:
- SP Entity ID (also called Audience URI or Identifier)
- ACS URL (Assertion Consumer Service URL, also called Reply URL)
- Metadata URL
- Verify your email domains
Add each email domain your team uses (for example,
yourcompany.com) and verify ownership by adding a DNS TXT record.For each domain, Lynkle provides:
- Host:
_lynkle-sso.yourcompany.com - Value: a unique verification token (shown in the dashboard)
Add this TXT record in your DNS provider, then click Verify in Lynkle. DNS changes can take up to 48 hours to propagate, but most providers update within a few minutes.
- Host:
- Configure policies
Once your IdP is connected and at least one domain is verified, you can enable Require SSO for all team members. This forces non-owner members to sign in through your IdP. Organization owners are always exempt so you can never be locked out.
Invite each person under Settings > People before they sign in with SSO. On their first SAML login, Lynkle uses the matching invitation to create their account if needed and activate their organization membership.
How team members sign in
Once SSO is configured, team members can sign in by clicking Single Sign-On (SSO) on the Lynkle login page and entering their work email. Lynkle checks the email domain and redirects them to your identity provider to authenticate.
The email returned by your IdP must belong to an active member or match a valid pending invitation for your Lynkle organization.
If SSO enforcement is enabled, members with a verified domain email will be required to use SSO and won't be able to sign in with a password or social login.
Organization owners can always sign in with any method, even when SSO enforcement is enabled. This prevents lockout scenarios.
Removing SSO
To remove your SSO configuration, first disable enforcement (if enabled), then click Remove SSO in the identity provider step. This removes the SAML configuration and all verified domains. Team members will need to sign in using another method.