
Custom SAML2: Single Sign-On with Flexopus
Connect Flexopus to your own Identity Provider via the SAML2 standard and enable your employees to log in securely and centrally managed – without additional passwords.
What is the Custom SAML2 integration?
SAML2 (Security Assertion Markup Language 2.0) is a widely used open standard for the secure exchange of authentication information between an Identity Provider (IdP) and a Service Provider (SP). Flexopus acts as a service provider and supports any identity provider that complies with the SAML2 standard.
The integration makes it possible to set up Single Sign-On (SSO) for Flexopus: users log in once to their corporate identity provider and automatically gain access to Flexopus – without separate login details. Basic user attributes such as name, email address and optional fields such as department or cost center are transmitted via SAML2 assertions.
What is the purpose of integration?
The Custom SAML2 integration seamlessly connects Flexopus to your existing IT infrastructure. Once an employee has authenticated with your Identity Provider, they will be automatically logged into Flexopus – without having to enter their password again.
Typical application scenarios include, for example:
- Companies that use their own or a less common identity provider (e.g., Keycloak, Ping Identity, Okta or a custom SAML2-compliant IdP) can still fully integrate Flexopus.
- Access control remains centrally with the Identity Provider: Administrators there determine which users or groups are allowed to log in to Flexopus.
- New employees are automatically created in Flexopus upon their first login – manual pre-setup is not required.
How easy is the integration?
The setup is done via the Flexopus administration page under Settings > Authentication. The necessary configuration parameters (Entity ID, ACS URL, metadata URL) are provided there, which you then enter into your Identity Provider. Next, upload your IdP metadata to Flexopus or specify the metadata URL.
It is also possible to configure multiple SSO providers simultaneously – practical for companies with multiple subsidiaries or IdPs.
For complete step-by-step setup instructions, please visit our Help Center.
What are the advantages of integration?
- Compatibility with any SAML2-compliant Identity Provider – regardless of manufacturer or system.
- Single Sign-On for your employees: one login, access to all connected systems – no additional password for Flexopus.
- Central access control: In the Identity Provider, you control who has access to Flexopus – based on users or groups.
- Automatic user creation upon first login: New employees do not need to be manually created in Flexopus.
- Synchronization of user attributes such as name, email, department, cost center or job title directly via SAML2.
- Increased security through signed SAML2 assertions and optional encryption of the transmitted data.
- Support for multi-factor authentication (MFA) – managed directly through your identity provider.
- Password login in Flexopus can optionally be disabled to enforce SSO as the only login method.
Categories
Developed By
Flexopus GmbHFurther integrations
questions and answers
Does the integration also work with our own identity provider, which is not on the list?
Yes. Flexopus implements the official SAML2 standard and is therefore fundamentally compatible with any SAML2-compliant Identity Provider – regardless of the manufacturer. Specific instructions are also available for common providers such as Microsoft Entra ID, Google, Keycloak, Okta, Ping Identity or Akamai.
What user data is transmitted via SAML2?
Required fields are first name, last name (or a combined name field) and email address. Optionally, additional attributes such as job title, department, cost center, or group memberships can be transferred. Only the data that you configure for transmission in your Identity Provider will be transmitted.
What happens when a user is removed from the Identity Provider?
If a user is deactivated or removed in the Identity Provider, they can no longer log in to Flexopus via SSO. Access will be automatically blocked. The user entry in Flexopus will remain until it is manually deleted there. For fully automatic deactivation or deletion, we recommend the additional use of the SCIM interface.
Is it possible to use password login alongside SSO?
Yes, by default both login methods can be active simultaneously. However, administrators can selectively disable password login to enforce SSO as the only login option. A hidden backup login remains accessible to administrators.
What should be considered regarding the User Principal Name (UPN)?
The UPN is a unique, unchanging identifier in SAML2. It should not be changed after the initial setup, as this can lead to duplicate user entries or assignment errors. Should a change be necessary, please contact Flexopus support.

