Bare.ID SAML2 SSO with Flexopus
With the Bare.ID SAML2 SSO integration, you can securely connect Flexopus to your corporate directory. Employees log in using their existing credentials—no need for separate passwords for Flexopus.
What is the Bare.ID SAML2 SSO integration?
SAML2 (Security Assertion Markup Language 2.0) is a widely used open standard for Single Sign-On (SSO). Flexopus fully supports the SAML2 standard, acting as a Service Provider (SP). Bare.ID takes on the role of the Identity Provider (IdP) and authenticates the users.
During login, Flexopus redirects the user to Bare.ID. Bare.ID verifies the identity and sends a signed authentication response (SAML2 Assertion) back to Flexopus. Flexopus uses this to retrieve user information such as name, email address, and optionally other attributes like department or cost center.
The connection is configured via metadata exchanged between Flexopus and Bare.ID. All transmissions are signed, ensuring the integrity of the login data.
What is the purpose of the integration?
The Bare.ID SAML2 SSO integration ensures that employees can use Flexopus without additional login credentials. They sign in once via Bare.ID and automatically gain access to Flexopus—exactly as configured for their account.
Typical use cases for the integration:
- Centralized access control: Administrators manage who has access to Flexopus via Bare.ID—without manual maintenance in Flexopus itself.
- Automatic user registration: New users are automatically created in Flexopus upon their first login. No manual profile creation required.
- User attribute synchronization: In addition to name and email address, department, job title, or cost center can optionally be transferred.
- Enforce SSO: Traditional email/password logins can be disabled so that all users log in exclusively via Bare.ID.
How easy is the integration?
Setup is performed via the Flexopus dashboard under Settings > Authentication. There, you create a new SAML2 provider and automatically receive the configuration parameters to enter into Bare.ID. Afterward, you upload the Bare.ID metadata to Flexopus or provide the metadata URL.
The setup is completed in just a few steps and requires no deep technical knowledge. You can find a complete step-by-step guide for the setup in our Help Center.
What are the benefits of the integration?
- Single Sign-On (SSO): Employees use their existing corporate credentials—no additional password for Flexopus.
- Higher security: Login occurs via signed SAML2 assertions. Additionally, Multi-Factor Authentication (MFA) can be enabled via Bare.ID.
- Centralized access management: Access to Flexopus is controlled directly via Bare.ID. If an employee leaves, access is automatically revoked.
- Automatic user creation: New users are registered automatically upon their first login—no manual effort for administrators.
- Flexible attribute transfer: Additional fields such as department, job title, or cost center can be synchronized optionally.
- Support for multiple Identity Providers: Flexopus supports multiple SAML2 providers simultaneously—ideal for companies with complex IT structures.
- Included for free: The SAML2 SSO integration is included in the Flexopus subscription (depending on the chosen plan) at no extra cost.
Further integrations
Questions and answers
What data is transferred between Bare.ID and Flexopus?
During login, Bare.ID only transfers the data necessary for authentication and user creation: first name, last name, and email address. Optionally, further attributes such as department, job title, or cost center can be transmitted if configured in Bare.ID. No passwords or security-critical access credentials are transferred.
What happens when an employee leaves the company?
As soon as access is deactivated or removed in Bare.ID, the affected person can no longer log in to Flexopus. The user profile in Flexopus remains for the time being but is no longer accessible. Administrators can subsequently deactivate or delete the profile manually in Flexopus.
Can I enforce SSO and disable email/password login?
Yes. In the Flexopus dashboard under Settings > Authentication, you can disable the traditional email/password login or hide the login form. This ensures that all users access Flexopus exclusively via Bare.ID SAML2 SSO. For administrators, an emergency access via a separate login URL remains available.
What happens when a user logs in for the first time?
By default, a new user profile is automatically created in Flexopus as soon as a user logs in via Bare.ID for the first time. Manual pre-creation of profiles is not required. This automatic registration can be disabled in the security settings if needed.
Can a duplicate user profile be created?
A duplicate profile can be created if a user's unique identifier (UPN – User Principal Name) is changed subsequently. It is therefore important not to change the UPN after setup. Should such an issue occur, the Flexopus support team will be happy to help.

