Who can use this feature?
🔐 Only team owners and admins can configure single sign-on (SSO)
⭐️ Available on the Business plan.
Log in to Nuclino.
Open your Team settings by opening the main menu in the top left corner of the app, clicking on your team name, and then choosing Team settings.
Go to the Authentication section and choose SAML-based single sign-on (SSO).
Note the ACS URL and Entity ID.
Make sure you are a Google Workspace super administrator for this task.
Go to the Google Admin console.
Go to Apps > Web and mobile apps and select Add app > Add custom SAML app.
Enter the App details and click Continue.
Note the SSO URL, Entity ID, and certificate text. You'll later need to enter the SSO URL, Entity ID, and the certificate text in your Nuclino team settings.
Fill out the form:
ACS URL: Enter your ACS URL from Step 1
Entity ID: Enter your Entity ID from Step 1
Check Signed response.
Name ID format: EMAIL
Name ID: Basic Information > Primary email
Set the following attributes:
Basic Information > First name → first_name
Basic Information > Last name → last_name
Click on the User access panel.
Select ON for everyone and click Save.
After configuring SSO, the changes need time to propagate to all users in Google Workspace, and in the first 24 hours, you may encounter a 403
or 500
error when authenticating via SSO on the Google Workspace login page. The time for propagation can vary from several hours all the way up to 24, depending on the size of your organization.
Log in to Nuclino.
Click the menu button in the top left corner to open the main menu.
Click on your team name and select Team settings.
Go to the Authentication section and choose SAML-based single sign-on (SSO)
Enter the following information
SSO URL: Enter the SSO URL you've noted in Step 2
IDP Entity ID: Enter the Entity ID you've noted in Step 2
Public certificate: Enter the certificate text you've noted in Step 2
Click Save changes.
Optional: Enforce single sign-on (SSO)
Your team can now sign up and log in via your team URL which you can find in your team settings in the Authentication section.
People who already have a Nuclino account with the same email address as their SSO account can choose to link this account. Afterwards, they can log in using their existing Nuclino account or use SSO instead.
For people who don't have a Nuclino account yet, a new account is provisioned when they log in for the first time using your team URL.
Users who have already set up SSO for their Nuclino account can also go to the normal login (https://app.nuclino.com/login) and select Log in via single sign-on (SSO).
Troubleshooting
After configuring SSO, the changes need time to propagate to all users in Google Workspace, and in the first 24 hours, you may encounter a 403
or 500
error when authenticating via SSO on the Google Workspace login page. The time for propagation can vary from several hours all the way up to 24, depending on the size of your organization.
Questions?
If you have any questions or need help to set up SSO for Nuclino, please contact us.