Skip to main content

How do I set up SSO in Rebrandly?

Set up single sign-on to manage your users and control Rebrandly access through your identity provider (IdP).

Rebrandly supports SSO with SAML 2.0 or OIDC, so you can authenticate through your existing identity provider, such as Okta, Microsoft Entra (Azure AD), Google Workspace, OneLogin, or any other SAML 2.0 or OIDC-compliant provider.

Before you begin: once SSO is set up, every new person who signs in for the first time is automatically granted access to all workspaces with the Reviewer role. If you want to limit access, plan to review and reassign teammate roles right after, both when you first enable SSO and any time a new teammate signs in through SSO for the first time.

To set up SSO

You'll need:

  • An admin account with an identity provider (IdP)

  • Account Owner role on your Rebrandly subscription. Only Account Owners can configure SSO.

  • The list of email domains your team signs in with (e.g., johndoe.com)

Start SSO setup

  1. Log in to Rebrandly. You must be the account Owner.

  2. Click your profile icon, then Settings, then Authentication.

  3. Select Set up SSO.

  4. You'll see an information screen explaining what you're about to set up. Click Next to continue.

Add your organization and domain

  1. Enter your organization name, a label for your configuration.

  2. Enter the email domain(s) your team signs in with (e.g., johndoe.com). If your team uses multiple domains, add each one.

  3. Click Save.

Complete setup with your identity provider

  1. Click Continue your configuration.

  2. Select your identity provider from the list (Okta, Microsoft Entra, Google Workspace, OneLogin, or another SAML 2.0/OIDC-compliant provider).

  3. Follow the step-by-step, provider-specific instructions shown in the portal.

  4. Test your connection before finishing.

What happens after setup

  • Changes take effect immediately, with no waiting for propagation.

  • All users log in at https://app.rebrandly.com.

  • New users signing in with SSO for the first time are automatically granted access to all workspaces with the Reviewer role. Go to the Teammates page afterward to assign the correct role and workspace access for each person.

  • Existing users on your domain are routed through SSO on their next login, and lose the ability to log in with a password from then on.

  • Account owners can disable SSO at any time from Authentication settings. Once disabled, people can log in again using a username and password.

If you already have SSO configured (legacy)

If your account already has the earlier SAML setup, you don't need to remove it first. You'll see both:

  • Your existing configuration, labeled Single sign-on (Legacy), fully functional and continuing to sign your team in exactly as before.

  • The new SSO setup, ready for you to configure using the steps above.

Your legacy configuration keeps working right up until the new setup is fully completed. Once it's active, the legacy option disappears from view.

If you later want to revert to the legacy SSO, deleting the new configuration automatically restores it. However, the legacy SSO will be retired sometime in the near future.

⚠️ If you are going to remove SSO, plan an access migration (e.g., re-enabling SSO under a new configuration) before removing it.

After SSO is disabled, users who were signing in via SSO can create a password by going to the login page and clicking "Forgot password?"

Did this answer your question?