BareID SAML2 SSO with Flexopus
With the Bare.ID SAML2 SSO integration, you can securely connect Flexopus to your company directory. Employees log in with their existing access data – without separate passwords for Flexopus.
What is the Bare.ID SAML2 SSO integration?
SAML2 (Security Assertion Markup Language 2.0) is a widely used open standard for Single Sign-On (SSO). Flexopus fully supports the SAML2 standard and acts as a Service Provider (SP). Bare.ID takes on the role of the Identity Provider (IdP) and authenticates the users.
During registration, Flexopus redirects the user to Bare.ID. Bare.ID verifies the identity and sends a signed authentication response (SAML2 Assertion) back to Flexopus. Flexopus reads user information such as name, email address and optionally other attributes such as department or cost center from this.
The connection is configured via metadata exchanged between Flexopus and Bare.ID. All transmissions are signed, thus ensuring the integrity of the login data.
What is the purpose of integration?
The Bare.ID SAML2 SSO integration ensures that employees can use Flexopus without additional login credentials. You register once via Bare.ID and automatically receive access to Flexopus – exactly as it is configured for your account.
Typical use cases for integration:
- Centralized access control: Administrators use Bare.ID to control which employees have access to Flexopus – without manual maintenance in Flexopus itself.
- Automatic user registration: New users are automatically created in Flexopus upon their first login. No manual profile creation is necessary.
- Synchronization of user attributes: In addition to name and email address, department, job title or cost center can optionally be transferred.
- Enforcing SSO: Classic email/password logins can be disabled, so that all users log in exclusively via Bare.ID.
How easy is the integration?
The setup is done via the Flexopus dashboard under Settings > Authentication. There you create a new SAML2 provider and automatically receive the configuration parameters that you enter into Bare.ID. Next, upload the Bare.ID metadata to Flexopus or enter the metadata URL.
The setup can be completed in just a few steps and requires no in-depth technical knowledge. For complete step-by-step setup instructions, please visit our Help Center.
What are the advantages of integration?
- Single Sign-On (SSO): Employees use their existing company login credentials – no additional password is required for Flexopus.
- Increased security: Registration is done via signed SAML2 assertions. Additionally, multi-factor authentication (MFA) can be activated via Bare.ID.
- Central access management: Access to Flexopus is controlled directly via Bare.ID. If an employee leaves the company, their access is automatically revoked.
- Automatic user creation: New users are automatically registered upon their first login – without any manual effort for administrators.
- Flexible attribute transfer: Additional fields such as department, job title or cost center can optionally be synchronized.
- Support for multiple Identity Providers: Flexopus supports multiple SAML2 providers simultaneously – ideal for companies with complex IT structures.
- Included free of charge: SAML2 SSO integration is included in the Flexopus subscription at no extra cost (depending on the chosen plan).
Further integrations
questions and answers
What data is transferred between Bare.ID and Flexopus?
During registration, Bare.ID transmits only the data necessary for authentication and user setup: first name, last name and email address. Optionally, additional attributes such as department, job title or cost center can be transmitted, provided these are configured in Bare.ID. No passwords or security-critical access data are transmitted.
What happens when an employee leaves the company?
Once access to Bare.ID is deactivated or removed, the affected person will no longer be able to log in to Flexopus. The user profile in Flexopus is initially retained, but is no longer accessible. Administrators can then manually deactivate or delete the profile in Flexopus.
Can I force SSO and disable email/password login?
Yes. In the Flexopus dashboard under Settings > Authentication, you can deactivate the classic email/password login or hide the login form. This ensures that all users access Flexopus exclusively via Bare.ID SAML2 SSO. An emergency access via a separate login URL will remain available for administrators.
What happens when a user logs in for the first time?
By default, a new user profile is automatically created in Flexopus as soon as a user logs in via Bare.ID for the first time. Manual pre-configuration of the profiles is not required. This automatic registration can be disabled in the security settings if needed.
Is it possible to create a duplicate user profile?
A duplicate profile can occur if a user's unique user identifier (UPN – User Principal Name) changes subsequently. Therefore, it is important not to change the UPN after setup. Should such a problem occur, the Flexopus support team will be happy to help.

