Skip to main content
Connect your organization’s identity provider to Invoca using the legacy Security Assertion Markup Language Single Sign-On (SAML SSO) setup, so your team can log in to Invoca through your existing identity provider instead of an Invoca username and password.
Important: Invoca has released a new SAML SSO configuration with an improved setup wizard and more features. All customers are expected to migrate to the Next-Gen SSO method by October 1, 2026. Use this guide only to troubleshoot an existing Legacy SAML SSO integration. For new setups, use the Next-Gen SSO implementation steps instead.

Overview

If your organization uses an identity provider, such as Microsoft Active Directory Federation Services (ADFS), Okta, or Azure, to log in to other apps, you can use that same provider to log in to Invoca. Identity providers use SAML SSO, a standard for exchanging login information, to communicate with apps like Invoca. Once enabled, anyone in your organization logging in to Invoca is redirected to sign in through your SSO provider instead, with no separate Invoca username or password required.

Prerequisites

To complete this guide, you must be logged in to Invoca as a user with the Super User role. Many of the steps also require access to your SAML identity provider’s administrative settings, which is typically handled by your organization’s IT or security team.

Step 1: Enable SAML SSO in your Invoca account

  1. Log in to Invoca, click Settings in the sidebar, then select Users.
  2. In the Users pane, click the menu button, then select SSO Settings. If you don’t see this option, confirm you’re logged in as a Super User; if you still don’t see it, contact your Invoca account team about enabling SAML SSO for your network.
  3. In the SAML SSO dropdown, choose how users should log in: Disabled (username/password only), Enabled – Mandatory for all users (SSO only), or Enabled – Optional for all users (either method).
  4. If your identity provider requires signed requests, check Require Signed Requests.
  5. Enter your identity provider’s Login URL, and optionally a Logout URL to support Single Logout. Sessions automatically log out after 30 minutes of inactivity.
  6. If required, enter your identity provider’s SHA-1 Fingerprint, with tuples separated by colons.
  7. Choose the Default Role to assign to new users signing in through SSO.
  8. Download your Invoca SAML metadata file at https://[your-network].invoca.net/sso/invoca-sso. You’ll need it for Step 2.

Step 2: Set up your identity provider

Every identity provider looks a little different, so field names may not match exactly. Configure your provider with:
  • Name ID format: urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress (Invoca uses email address as the unique user identifier).
  • Entity ID: Invoca_SAML_Service_Provider.
  • Assertion Consumer Service URL: https://[your-network].invoca.net/sso/consume.
  • Single Logout endpoint: https://[your-network].invoca.net/sso/logout.
  • User attributes for each user: first_name, last_name, and contact_phone_number (required); role, organization_type, organization_id_from_network, time_zone, report_filters, and licenses (optional, with defaults). For any attribute not listed here, use the name format urn:oasis:names:tc:SAML:2.0:attrname-format:basic.

Microsoft ADFS-specific setup

If ADFS is your identity provider, create a Relying Party Trust for Invoca (skip selecting a certificate, since Invoca doesn’t support encrypted communication for this feature), set the service and relying-party-identifier URLs above, and configure claims rules to send email, first name, last name, and phone number as outgoing claims. Set the Assertion Consumer and Logout endpoints under the trust’s Endpoints tab, and change the signature hash from SHA-256 to SHA-1 under the Advanced tab. Retrieve your token-signing certificate’s fingerprint from Service > Certificates, and enter it, colon-delimited, in Invoca’s SHA-1 Fingerprint field from Step 1. Microsoft’s own documentation covers the detailed screens for each of these steps, since they change between ADFS versions.

Support

Because every identity provider is configured a little differently, contact your Invoca account team if you’d like more hands-on help connecting your specific provider.
Last modified on September 30, 2026