---
title: "Set up SSO with OneLogin"
description: "This step-by-step guide explains how to set up Single Sign-On in Contentstack with OneLogin as your SAML 2.0 Identity Provider (IdP)."
url: "https://www.contentstack.com/docs/administration/set-up-sso-with-onelogin"
product: "Contentstack"
doc_type: "guide"
audience:
  - developers
  - admins
version: "current"
last_updated: "2026-07-28"
---

# Set up SSO with OneLogin

This step-by-step guide explains how to set up [Single Sign-On](/docs/administration) in Contentstack with OneLogin as your SAML 2.0 Identity Provider (IdP). You configure an SSO name in Contentstack, set up the Contentstack app in OneLogin, exchange the IdP details, add users and roles, optionally map roles, and then test and enable SSO.

## Prerequisites

*   [Contentstack account](https://www.contentstack.com/login)
*   OneLogin administrator account

## What You Will Learn

*   How to create an SSO name and ACS URL in Contentstack.
    
*   How to configure the Contentstack app in OneLogin as a SAML 2.0 IdP.
    
*   How to map OneLogin roles to Contentstack roles (optional).
    
*   How to test and enable SSO for your organization.
    

## Steps to Set up SSO with OneLogin

To do so, this integration requires following steps:

1.  [Create SSO Name and ACS URL in Contentstack](#create-sso-name-and-acs-url-in-contentstack)
2.  [Configure Contentstack App in OneLogin](#configure-contentstack-app-in-onelogin)
3.  [Configure OneLogin details in Contentstack](#configure-onelogin-details-in-contentstack)
4.  [Manage users access control in OneLogin](#manage-users-access-control-in-onelogin)
    1.  [Add application to users](#a-add-application-to-users)
    2.  [Add application to user groups for IdP Role Mapping](#b-add-application-to-user-groups-for-idp-role-mapping)
5.  [Create Role Mappings in Contentstack](#create-role-mappings-in-contentstack)
6.  [Test and Enable SSO](#test-and-enable-sso)

Let us see each of the processes in detail.

1.  ## Create SSO Name and ACS URL in Contentstack
    
    1.  Log in to your [Contentstack account](https://app.contentstack.com/#!/login), go to the **Organization Settings** page, and click on the **Single Sign-On** tab.![Set\_up\_SSo\_1\_highlighted.png](https://images.contentstack.io/v3/assets/blt23180bf2502c7444/blt7d698fba6693e892/60df360592aa422edd5e31cd/Set_up_SSo_1_highlighted.png)
    2.  Enter an **SSO name** of your choice, and click **Create**. For example, if your company name is “Acme, Inc.” enter “acme” here. This name will be used as one of the login credentials by the organization users while signing in.
        
        **Note:** The SSO Name can contain only alphabets (in lowercase), numbers (0-9), and/or hyphens (-).
        
         ![Set\_up\_SSo\_2\_highlighted.png](https://images.contentstack.io/v3/assets/blt23180bf2502c7444/bltaef848f532cb89b5/60df36337c871833cab137b5/Set_up_SSo_2_highlighted.png)Let's use “sso-test” as the **SSO Name**.
    3.  This will generate **Assertion Consumer Service (ACS)** URL and other details such as **Entity ID**, **Attributes** and **NameID** Format. These details will be used in **Step 2** for configuring the Contentstack app in OneLogin. ![Set\_up\_SSo\_3\_highlighted.jpg](https://images.contentstack.io/v3/assets/blt23180bf2502c7444/bltcfa122bf4ae86eb0/638768410fd02e10825078a8/Set_up_SSo_3_highlighted.jpg)  
          
        Keep this window open, as you may need these details for setting up the Contentstack app in OneLogin.
2.  ## Configure Contentstack App in OneLogin
    
    **Note:** You will need to be a OneLogin administrator to complete the below steps.
    
    1.  Log into your OneLogin Admin account, click on the **APPS** tab and click on the **ADD APP** button on the top right corner. 
    2.  From the applications displayed on the page, use the **SAML Test Connector (IdP)** application.![onelogin-add-app.png](https://images.contentstack.io/v3/assets/blt23180bf2502c7444/blt7a27f745cf5afb2b/5f467abfc0e5e047f9386ea8/onelogin-add-app.png)
    3.  Set the **Display Name** for your Contentstack application, for example “Contentstack” and click **Save.**![onelogin-configuration-step-1.png](https://images.contentstack.io/v3/assets/blt23180bf2502c7444/blt9bc14deff336d42c/5f467abf2a722a66860bd9df/onelogin-configuration-step-1.png)
    4.  Log into your Contentstack account as the Owner and get your “Single sign on URL” for OneLogin. In Contentstack, it’s called **Assertion Consumer URL** and you can find it in **Organization Settings** > **SINGLE SIGN-ON**.  
        ![ACS\_URL.png](https://images.contentstack.io/v3/assets/blt23180bf2502c7444/bltbbd19c8098a9cc1f/63762ef176567a10a7cb82c1/ACS_URL.png)
    5.  Now, click on the **Configuration** tab, opy the “ACS URL” from the above step and paste it into the **ACS (Consumer) URL Validator** field in OneLogin. Paste the same value into the **ACS (Consumer) URL** field as well.![onelogin-configuration-step-2-a.png](https://images.contentstack.io/v3/assets/blt23180bf2502c7444/bltce0a3228389e0a86/5f467abfa5031b4a3bba8c94/onelogin-configuration-step-2-a.png)
    6.  Go to the **Parameters** tab and add parameters. By default, the first parameter is **NameID**. We will set its value to **Email** by clicking on the parameter and selecting it from the dropdown.![onelogin-configuration-step-2-b.png](https://images.contentstack.io/v3/assets/blt23180bf2502c7444/blt7f98768306f8cba3/5f467abf3c3c0b6617212bcb/onelogin-configuration-step-2-b.png)
    7.  Click on the **Add parameter** link, add a parameter named **first\_name**, select the **Include in SAML assertion** checkbox, and click on **Save**.![onelogin-configuration-step-3.png](https://images.contentstack.io/v3/assets/blt23180bf2502c7444/blta025f3e144f1b114/5f467abf0341654a3a76ea8c/onelogin-configuration-step-3.png)
    8.  Next, we will assign a value for the created field. Click on the **Value** dropdown, select **First Name**, and click on **Save**.![onelogin-configuration-step-3-a-1.png](https://images.contentstack.io/v3/assets/blt23180bf2502c7444/blt29a3d53c2a215324/5f467aeba5031b4a3bba8c9c/onelogin-configuration-step-3-a-1.png)  
        Similarly, we will add two more attributes. Add **last\_name** and select **Last Name** as the value, and add **email** and select **Email** as the value. Finally, your attribute list will look as follows:  
        ![onelogin-configuration-step-3-b.png](https://images.contentstack.io/v3/assets/blt23180bf2502c7444/blt28d684a86f17b70f/5d650d2dd84c39242e05d24e/Parameters.png)
    9.  \[_**Optional Step**_\] If you want to map IdP roles to Contentstack roles, you need to add a new attribute called roles. Check the **Include in SAML assertion** and click on **Save**.
    10.  Select **Users Roles** as the **Value** and click on **Save**.
    
    **Note:** Perform steps 8 and 9 only if [IdP Role Mapping](/docs/administration/idp-role-mapping) is part of your Contentstack plan.
    
3.  ## Configure OneLogin details in Contentstack
    
    1.  Click on the **SSO** tab of your Contentstack application in OneLogin, you will see the **SAML 2.0 Endpoint (HTTP)** URL field.![onelogin-configuration-step-4.png](https://images.contentstack.io/v3/assets/blt23180bf2502c7444/bltd497ac0e9582ee2b/5f467aeb70ca0f65ba109692/onelogin-configuration-step-4.png)
    2.  Click on the “Copy to Clipboard” icon beside the **SAML 2.0 Endpoint (HTTP)** field or you can just manually copy the URL.
    3.  Then, in the Contentstack **Single Sign-On** page, go to **2 IdP Configuration**, and paste the copied URL into the **Single Sign-on URL** field.![Set\_up\_SSo\_4\_highlighted.png](https://images.contentstack.io/v3/assets/blt23180bf2502c7444/blt18f2f24a0807ee73/60df36992eb77d200fac88ec/Set_up_SSo_4_highlighted.png)
    4.  Now, in the **SSO** tab, click on **View Details** under the **X.509 Certificate** parameter.![onelogin-configuration-step-4-a.png](https://images.contentstack.io/v3/assets/blt23180bf2502c7444/blt5b625cec4322e1b5/5f467aeb2a722a66860bd9e3/onelogin-configuration-step-4-a.png)
    5.  The **Standard Strength Certificate (2048-bit)** window displays the details of the certificate. Click on the **DOWNLOAD** button to download the certificate.![onelogin-configuration-step-4-1-1.png](https://images.contentstack.io/v3/assets/blt23180bf2502c7444/blt728e1023fc5f2d2f/5f467aebfb60b1668c21d8db/onelogin-configuration-step-4-1-1.png)
    6.  Upload the X.509 certificate that you downloaded into the **Certificate** field in Contentstack.
4.  ## Manage users access control in OneLogin
    
    After setting the necessary configurations in Contentstack, you need to now assign the newly added application to your users.
    
    ### A - Add application to users
    
    1.  You can assign a single user under **Users** > **All Users**. OneLogin will automatically retrieve the list of potential users that are currently logged in to OneLogin based on the user’s email address.![onelogin-user-step-1.png](https://images.contentstack.io/v3/assets/blt23180bf2502c7444/bltd58882a98939cf66/5f467aeba21dbd47faf25eeb/onelogin-user-step-1.png)
    2.  Click on the **NEW USER** button at the top right corner to add new users to Contentstack. Add the user’s **Email** address, **First Name**, and **Last Name**.![onelogin-configuration-step-5.png](https://images.contentstack.io/v3/assets/blt23180bf2502c7444/blt0393f094f79ef0f4/5f467aebb008d84afeba6bcf/onelogin-configuration-step-5.png)
    3.  Now, on the **Applications** tab, click on the **+** icon beside the **Applications** bar, and select your app in the **Select Application** dropdown. Then, click on **CONTINUE**![onelogin-configuration-step-5-a.png](https://images.contentstack.io/v3/assets/blt23180bf2502c7444/blt2c605b280c5416bf/5f467aebc0e5e047f9386eac/onelogin-configuration-step-5-a.png)You will be led to the **Edit Contentstack Login For Demo User** window where you can verify the details. Click on **Save**.
    
    With this, you are done with setting up the Contentstack app in OneLogin. Proceed to configuring the remaining steps in Contentstack SSO in [Step 6](#test-and-enable-sso).
    
    But, if you want to perform IdP Role Mapping and allow user groups to directly log in to your SSO-enabled organization (without invitation) with the assigned permissions through role mapping, perform **Step 4.B**.
    
    ### B - Add application to user groups for IdP Role Mapping
    
    _**Perform this step only if IdP Role Mapping is part of your Contentstack plan.**_
    
    This is an alternate way of managing users and permissions of your SSO-enabled organization. [IdP Role Mapping](/docs/administration/idp-role-mapping) allows you to map your IdP roles to Contentstack roles while configuring SSO for your organization.
    
    1.  You can assign a role under **Users** > **Roles**. OneLogin will automatically retrieve the list of potential user roles that are currently in your OneLogin account.
    2.  To add a new role, click on the **NEW ROLE** button located at the top right corner to add a new user role.  
        ![Click on ](https://images.contentstack.io/v3/assets/blt23180bf2502c7444/bltc939934ac2ffe713/5d650d210d77ee2fe445edec/Role_list.png)
    3.  You will be allowed to assign a role name. Provide a role name and click on the check (**✓**) icon.
    4.  Select the apps that you want to assign the role under the **Select Apps to Add** section.  
        ![New\_Role\_and\_Assign\_Apps.png](https://images.contentstack.io/v3/assets/blt23180bf2502c7444/blt93df320e4628b934/5f467abe185efb660c1ca5f9/New_Role_and_Assign_Apps.png)
    5.  Click on **Save**.
    
    You can now proceed to create role mappings in Contentstack for the IdP roles you created. Go to the **3\. User Management** section of your Contentstack SSO settings and perform Step 5.
    
5.  ## Create Role Mappings in Contentstack
    
    In the **User Management** section, you will see the following steps:
    
    1.  **Strict Mode**: Enable [**Strict Mode**](/docs/administration/set-up-sso-in-contentstack#strict-mode)if you do not want any users to access the organization without SSO login.
    2.  **Session Timeout**: The [**Session Timeout**](/docs/administration/set-up-sso-in-contentstack#session-timeout)lets you define the session duration for a user signed in through SSO. While the default is set to 12 hours, you can modify it as needed.
    3.  **Advanced Settings**: Click on [**Advanced Settings**](/docs/administration/set-up-sso-in-contentstack#advanced-settings) to expand the IdP Role Mapping section to map IdP roles to Contentstack.[  
        ](/docs/administration/set-up-sso-in-contentstack#advanced-settings)
        1.  In the Add Role Mapping section, click on the **\+ ADD ROLE MAPPING** link to add new IdP role mapping and enter the following details:
            
            1.  **IdP Role Identifier**: Enter the IdP group/role identifier, for example, “Contentstack Developers.”
            2.  **Organization Role**: Assign either the **ADMIN** or **MEMBER** role to the mapped group/role.
            3.  **Stack Roles** _(optional)_: Assign [stacks](/docs/headless-cms/about-stack) as well as the corresponding stack-level roles to this role.  
                ![Set\_up\_SSo\_7\_highlighted.png](https://images.contentstack.io/v3/assets/blt23180bf2502c7444/bltbcf531ce26d6093e/60df36c30f2b3833d0f68f26/Set_up_SSo_7_highlighted.png)
            
            Likewise, you can add more role mappings for your Contentstack organization. To add a new Role mapping, click on **\+ ADD ROLE MAPPING** and enter the details.
        2.  Enter **;** (semicolon) in the **Role Delimiter** textbox.
        3.  Finally, check the **Enable IdP Role Mapping** checkbox to enable the feature.
    4.  Click on **Next** to continue further.
    
    While some details about these steps are given below, you can refer to our [general SSO guide](/docs/administration/about-single-sign-on-sso) for more information.
    
6.  ## Test and Enable SSO
    
    Next, you can try out the “Test SSO” and “Enable SSO” steps in Contentstack.
    
    ### Test SSO
    
    Before enabling SSO, it is recommended that you test the SSO settings configured so far. To do so, perform the following steps
    
    1.  Click on the **Test SSO** button and it will take you to Contentstack’s **Login Via SSO** page, where you need to specify your organization SSO name.
    2.  Then, click on **Continue** to go to your IdP sign-in page.
    3.  Sign in to your account. If you are able to sign in to your IdP, your test is successful. On successful connection, you will see a success message as follows:  
        ![Set\_up\_SSo\_10\_no\_highlight.png](https://images.contentstack.io/v3/assets/blt23180bf2502c7444/blt0f47d82021908c2c/60df36d17c871833cab137b9/Set_up_SSo_10_no_highlight.png)
    4.  If you have enabled IdP Role Mapping, you’ll find the following details in a new page:
        *   **SSO connection established successfully** - A success message is displayed.
        *   **IdP Roles received** - The list of all the roles assigned to you in your IdP.
        *   **Contentstack-IdP role mapping details** - The details of all the Contentstack Organization-specific and Stack-specific roles mapped to your IdP roles.
    5.  Click on the **Close** button. Now, you can safely enable SSO for your organization.
    
    **Note**: While testing SSO settings with IdP Role Mapping enabled, the test will be performed only for the IdP roles of the currently logged-in user (i.e., the Owner performing the test).
    
    ### Enable SSO
    
    Once you have tested your SSO settings, click **Enable SSO** to enable SSO for your Contentstack organization.
    
    ![Set\_up\_SSo\_9\_highlighted.png](https://images.contentstack.io/v3/assets/blt23180bf2502c7444/bltac9e068d24baccc9/60e335dd92aa422edd5e38d7/Set_up_SSo_9_highlighted.png)
    
      
    Confirm your action by clicking on **Yes**.
    
    Once this is enabled, users of this organization can access the organization through SSO. If needed, you can always disable SSO from this page as well.
    
    ![Disable\_SSO.png](https://images.contentstack.io/v3/assets/blt23180bf2502c7444/bltd804680545216a38/63762ef15834861044c1f25b/Disable_SSO.png)