Rebrandly's SSO setup supports SAML 2.0 and OIDC-based Single Sign-On. Support differs slightly depending on whether your account uses the current setup or the earlier (legacy) SAML-only setup.
If you don't see the Legacy SSO card...
This means your SSO is using the latest version of our connector, and these features are included.
Supported? | Detail |
✅ | SAML 2.0 or OIDC protocol |
✅ | SP-initiated login flow |
✅ | Live connection testing during setup |
✅ | Real-time configuration changes — no propagation delay |
✅ | Automatic user provisioning on first SSO login (new users default to the Reviewer role across all workspaces; the account Owner assigns specific roles afterward) |
✅ | SCIM directory sync — available as a separate paid add-on |
❌ | IdP-initiated login (tiles in your IdP portal that launch Rebrandly directly) |
❌ | Group or attribute-based workspace routing (routing users to different workspaces based on IdP group) |
Legacy SSO (SAML 2.0 only)
If your account still shows a Single sign-on (Legacy) block, that configuration supports:
Supported? | Detail |
✅ | SAML 2.0 protocol only |
✅ | SP-initiated login flow |
✅ | Automatic user provisioning by domain, with an admin-set default role and workspace |
❌ | SCIM directory sync |
❌ | IdP-initiated login, Single Logout (SLO), and group claims |
If you'd like to move to the new features, see How do I set up SSO for Rebrandly? and Why am I seeing a new SSO setup option?

