Set up Single Sign-On (SSO)
Set up Single Sign-On (SSO) to sign in to Fern using your existing identity provider.
SSO setup requires working with Fern to exchange configuration values (like callback URLs and entity IDs). To get started, select your identity provider below (Okta, Google Workspace, or Microsoft Entra), then choose SAML or OIDC.
Using another provider?
If you use another IdP, Fern will help you configure it. Reach out via Slack or support@buildwithfern.com to get started.
Okta
SAML
OIDC
Receive configuration values from Fern
Fern will send you the SSO URL and Audience URI through a secure channel (not Slack/email).
Create and configure application in Okta
In Applications, create a new app integration using SAML 2.0. Configure with these values:
Then, add attribute statements:
Send Fern your IdP metadata
From the Sign-On tab, copy the Metadata URL and X.509 certificate. Send them back to Fern. Fern will enable the connection and run a test login with you.
Google Workspace
SAML
Receive configuration values from Fern
Fern will send you the ACS URL and Entity ID through a secure channel (not Slack/email).
Create and configure application in Google
In Web and mobile apps, choose Add app → Add custom SAML app. On Service provider details, enter these values:
Then, add attribute statements:
Microsoft Entra
SAML
Create an application
Under Enterprise applications, select New application → Create your own application → Non-gallery.
Receive configuration values from Fern
Fern will send you the Identifier (Entity ID) and Reply URL (ACS) through a secure channel.
Send Fern your IdP metadata
From SAML Certificates, copy the App Federation Metadata URL. Send it to Fern. Fern will enable the connection and run a test login with you.