SAML SSO
Let your organization sign in through your own identity provider — any SAML 2.0 IdP, managed by an org admin.
Sign in through your IdP
Anoman supports SAML single sign-on for organizations, via saml-jackson. An org admin registers a SAML connection to your identity provider; members then sign in through that IdP — Okta, Azure AD, Authentik, or any SAML 2.0 provider.
MFA-exempt: SSO-authenticated users skip Anoman's separate email-OTP MFA — your IdP has already vouched for them (and typically enforces its own MFA).
Register & manage connections
Connection management is admin-role and audited. POST /anoman/v1/sso/connections registers a connection and returns a slug plus the ACS URL and entity metadata to give your IdP. GET lists connections, and DELETE deactivates one.
Register a connection
List / deactivate
From IdP to Anoman session
A member hits GET /auth/sso/{slug}/login and is 302-redirected to your IdP. After the IdP authenticates them, it POSTs the SAML assertion (POST binding) to POST /auth/sso/callback, and Anoman issues a session.
Login flow
Where to configure it
Create, list, and deactivate connections in the dashboard at /dashboard/settings/sso — tier-gated to Pro and Enterprise.
Every SSO action is audited: sso.connection_created, sso.connection_deactivated, and sso.login on each IdP return.
Related: Organizations (roles & membership) and Audit log (where the sso.* events land).
Set up SSO
Register your SAML connection from the SSO settings page (Team & Enterprise).