Authentication

Validio supports user and password and SAML 2.0 single sign-on authentication methods.

Validio supports the following authentication methods:

  • User and password (default) — credentials held in Validio by the local identity provider. See User and Password.
  • Single sign-on (SSO) — authentication through your organization's identity provider, using SAML 2.0.

You can run more than one method at a time, so single sign-on can sit alongside password access rather than replacing it. Each method is configured as an identity provider under Workspace > Users > Identity Providers. For the configuration steps, see Managing Users and Identity Providers.

User and Password

The local identity provider authenticates users with credentials held in Validio, and is the default for a new workspace. On a VPC deployment, the first sign-in uses the admin credentials created in the Kubernetes Secret during installation.

When you create a user, check Create username and password to assign credentials manually. Users change their own password from the Account page, which also lists the password requirements Validio enforces. For more information, see Platform Configuration.

Guest Access Alongside SSO

The Guest login type is the exception to single sign-on. A Guest signs in with a username and password even when the local identity provider is disabled, which makes it the way to give access to external support users who are not part of your SSO provider. Guests can view everything and modify nothing, whatever role they hold. For how login types and global roles interact, see Login Types.

Single Sign-On

Single sign-on lets your team authenticate through your organization's identity provider instead of managing a second set of credentials in Validio. Validio supports SAML 2.0, which you can set up with Google Workspace, JumpCloud, Microsoft Entra ID, Okta, or CyberArk. For the provider-specific steps, see SAML SSO.

Provisioning Users Automatically

A SAML identity provider can also provision users and teams for you. Enabling SCIM generates an API key that your identity provider uses to push new users, profile updates, and groups into Validio, and to set users to inactive when they are removed upstream. For more information, see SCIM Synchronization.

Managing Identity Providers

Two rules are worth knowing before you change how people sign in:

  • Disabling is reversible. Check Disable this provider to stop users authenticating through it. You can enable it again later by updating the provider.
  • The last provider cannot be deleted. Deleting an identity provider is only offered when your workspace has more than one configured, so you cannot lock everyone out.

Did this page help you?