Set up Single Sign-On (SSO)
Set up Single Sign-On (SSO)
Set up Single Sign-On (SSO)
This feature is available only for the Enterprise plan. To get started, reach out to support@buildwithfern.com.
Set up Single Sign-On (SSO) to sign in to Fern using your existing identity provider.
SSO setup requires working with Fern to exchange configuration values (like callback URLs and entity IDs). To get started, select your identity provider below (Okta, Google Workspace, or Microsoft Entra), then choose SAML or OIDC.
If you use another IdP, Fern will help you configure it. Reach out via Slack or support@buildwithfern.com to get started.
Fern will send you the SSO URL and Audience URI through a secure channel.
In Applications, create a new app integration using SAML 2.0. Configure with these values:
Then, add attribute statements:
From the Sign-On tab, copy the Metadata URL and X.509 certificate. Send them back to Fern. Fern will enable the connection and run a test login with you.
Fern will send you the ACS URL and Entity ID through a secure channel.
In Web and mobile apps, choose Add app → Add custom SAML app. On Service provider details, enter these values:
Then, add attribute statements:
Under Enterprise applications, select New application → Create your own application → Non-gallery.
Fern will send you the Identifier (Entity ID) and Reply URL (ACS) through a secure channel.
From SAML Certificates, copy the App Federation Metadata URL. Send it to Fern. Fern will enable the connection and run a test login with you.