SSO Setup for SocialHub Account
Enabling SSO for a SocialHub account requires manual setup from our side and can't be done by yourself. Please reach out to us if you want to use SSO for your SocialHub Account.
Important:
- The moment SSO is activated, username / password login is disabled for all users in your account. Generic / shared logins (e.g.
tagschicht1@company.de) not backed by your IdP will lose access permanently.- Usernames in SocialHub must match the username sent by your Identity Provider.
Information we need from you
General
| What | Example |
|---|---|
| Identity Provider | Azure Entra ID, Google, on-premise Active Directory, GitHub, … |
| Protocol | SAML |
| Metadata URL (SAML) | https://login.microsoftonline.com/<tenant-id>/federationmetadata/2007-06/federationmetadata.xml?appid=<app-id> |
The metadata URL must include the ?appid=<app-id> parameter - tenant-level metadata will not work.
What you need to configure on your side
Once we're set up on our end, we'll send you these values:
| Your IdP setting | Example |
|---|---|
| Identifier (Entity ID) | https://keycloak.socialhub.io/realms/<your-realm> |
| Reply URL (ACS) | https://keycloak.socialhub.io/realms/<your-realm>/broker/saml/endpoint |
| Relay State | https://keycloak.socialhub.io/realms/<your-realm> |
Process & timing
- Please inform us which Identity Provider you intend to use.
- You schedule a half-hour setup session with our DevOps-Department and your IT-Team, where we exchange the SAML details. Your Account Manager happily provides the contact.
- We coordinate the switchover - decide if you need a maintenance window.
- We perform the switch to SSO. Ideally one of your users is available to test SSO directly.
- After activation, all users log in via a single SSO link (we provide it). The link is permanent and identical for all users in your account. After the switch, login via user / password is no longer possible.