Enterprise identity
One identity provider. One audit trail. Zero lockout anxiety.
Federated login with every major IdP, automated user lifecycle via SCIM 2.0, self-serve configuration, and the guardrails regulated buyers require.
Supported identity providers
Every tenant configures their own IdP through our self-serve admin UI — SkillMind operators never see your credentials.
Ping, OneLogin, JumpCloud, and any generic SAML 2.0 or OpenID Connect IdP also work against the same endpoints.
What enterprise identity looks like on SkillMind
Eight capabilities, each gated by an explicit configuration surface in the tenant admin UI.
Federated single sign-on
SAML 2.0 assertion consumer endpoints and OpenID Connect authorization-code-with-PKCE, per tenant, per protocol. Switch between SAML and OIDC without losing configuration.
Automated provisioning
Full SCIM 2.0 Users and Groups surface (POST, GET, PATCH, PUT, DELETE) with ETag concurrency control and RFC 7644 filter support. Plug your HR system or IdP directly into us.
Per-tenant self-serve
Every tenant admin configures their own IdP, rotates their own certificates, issues their own SCIM tokens. No support tickets, no operator credential sharing.
Certificate trust pool
Rotate SAML signing certificates without a maintenance window — old and new certificates live side by side in the trust pool until you remove the old one.
JIT and strict mode
Create users on first SSO login by default, or flip on strict mode to reject any subject not pre-provisioned via SCIM. Your security team picks the posture.
Domain verification
Route SP-initiated login to the correct tenant via DNS TXT challenge ownership. Re-verified every 90 days automatically. First-claim-wins cross-tenant collision handling.
Break-glass safeguards
Designated admins keep local-password access even when SSO is enforced tenant-wide. The system refuses to leave you with zero break-glass accounts. Operator recovery for the worst-case.
Complete audit trail
Every login, every SCIM mutation, every configuration change, every certificate rotation — recorded with correlation IDs, exportable on demand for SOC 2 reviews.
Built for regulated buyers
The surface your security team will ask about — already in place.
SOC 2 Type II scoped
Identity-relevant events land in the audit log within 5 seconds. Every assertion, every provisioning call, every configuration change.
GDPR-compatible
Identity linkage participates in Article 17 erasure and Article 20 export via the same registry that every other module uses.
Auditor-ready in one week
Give an external auditor read access to the audit log and they can reconstruct any user's complete identity history — assertions, role transitions, and all.
See it in the product
Screenshots from the tenant-admin console; each wizard matches the integration-guide screenshots one-to-one.
- Settings · IdentitySingle sign-onEnforce SSOAll non-break-glass users sign in through your IdP.Strict modeReject unfederated sessions on emergency console URLs.OkOktaConnected · 2 minutes ago
Configuration overview — the single surface your IT admins operate from. - Single sign-on · SAML wizardConfigure SAML✓Provider2Metadata3Mapping4VerifyIdentity provider metadata URLhttps://idp.example.com/sso/saml/metadataMetadata parsedIssuerhttps://idp.example.comCert SHA-2563a:8f:2c:1d:…Expires2028-04-18
SAML wizard — upload metadata XML or fetch by URL, certificate added to the trust pool automatically. - Identity · ProvisioningSCIM tokensToken displayed onceCopy the secret now — we store only the SHA-256 hash and cannot reveal it again.scim_pat_3a8f2c1d••••••••Production · Oktaread:users write:usersStaging · Entraread:users write:groupsPilot tenantread:users
SCIM tokens — issue, rotate, revoke. New tokens are displayed once; stored as SHA-256 hashes. - Identity · AuditRecent identity eventsAuthenticationProvisioningConfiguration2026-04-30 14:22a.khoury@meridian.coauth.login.sso.success2026-04-30 14:18system · scimscim.user.created2026-04-30 13:54system · scimscim.group.updated2026-04-30 12:41unknownauth.login.sso.failed2026-04-30 11:32d.park@skillmind.cosso.config.changed
Identity audit — filtered view of the last seven days of logins, provisioning calls, and configuration edits.
Integration guides
Step-by-step walkthroughs for every major IdP. Pair with your tenant-admin UI for a 30-minute onboarding.
Ready to ship enterprise-ready SSO to your team?
Talk to our team about a pilot. We stand up a sandbox tenant pointed at your IdP within one business day.