The URLs below show their expected format. Refero will provide the complete ACS URL and Entity ID for your workspace.
Prerequisites
- A Team subscription or custom enterprise agreement with the SSO add-on
- Admin access to your identity provider
- The company email domain to enable for SSO
Request SSO
To discuss pricing and setup requirements, email mike@refero.design with:- Your company name and expected number of Refero seats
- Your identity provider and company email domain or domains
- Your rollout expectations, preferred timeline, and any security requirements
How setup works
- Refero confirms the commercial terms and setup scope with your team.
- Refero gives you the workspace-specific ACS URL and Entity ID.
- Your IT team creates a SAML application for Refero and sends the IdP metadata to mike@refero.design.
- Refero enables SSO routing and JIT provisioning for your configured company domains.
- Your team tests sign-in before rolling SSO out to the workspace.
SAML configuration
{organization_sso_id} is a placeholder. Do not copy it as-is or reuse an ID from another workspace.
User identifier
Refero requires an email-like identifier in the SAML assertion. Set the user’s email address as the Name ID using theemailAddress format. Refero uses this email to find an existing account or create a new one.
Refero also recognizes common email attributes as fallbacks, but Name ID is the preferred configuration.