Set up SAML single sign-on for your site

Enabling SAML Single Sign-On

What is SAML SSO?

SAML Single Sign-On (SSO) lets you log in to multiple web applications using a single identity provider login. Instead of managing separate credentials for each application, you authenticate once with your identity provider and gain access to all connected applications.

Key benefits include:

  • Reduced password fatigue — you remember only one set of credentials
  • Faster access — no repeated login prompts across applications
  • Improved security — centralized authentication management

Common SAML SSO providers include Okta, OneLogin, and Auth0. For Bettermode-specific setup instructions, see the related topics at the end of this article.

SAML SSO Flow

Once SAML SSO is enabled on your Bettermode site, users can log in without manually creating an account or entering credentials. Instead, they authenticate through your configured SAML provider.

How the login process works

  1. User selects the SAML login option on the site login page
  2. User authenticates with the identity provider
  3. User gains immediate access to the site without additional credential entry

Create new staff

The "Create new staff" toggle determines whether new user accounts are automatically provisioned:

  • Enabled: When a user logs in via SAML for the first time, Bettermode automatically creates a staff account if that user doesn't already exist. You can assign Admin or Moderator roles to these accounts later. See How to assign roles for details.
  • Disabled: Bettermode displays an error and does not create an account. This setting ensures only pre-approved staff can register via SAML.

Login button text

Use this setting to control whether the SAML login option appears on your public login page:

  • Enter text: The SAML button displays on the login and sign-up pages with your specified text (e.g., "Log in with Okta").
  • Leave empty: The SAML button is hidden from the public login page. Staff can still access the site by logging into their identity provider and navigating directly, or accessing the site through their identity provider's application portal.

Example: If you use Okta only for admin and staff authentication, you might leave this field empty to prevent general site users from seeing a staff-only login option.

How to set up SAML SSO in Bettermode

  1. Log in to your Bettermode site with your admin account.
  2. Navigate to Administration > Settings > Authentication.
  3. Enable the SAML toggle.
  4. On the SAML settings page, fill in all required credentials (see SAML SSO Settings below).
  5. Enable the "Enable SAML" toggle at the bottom of the page.
  6. Click Update to save your changes.

SAML SSO Settings

Identity Provider settings

Obtain the following credentials from your identity provider's admin console (e.g., Okta, OneLogin). Each provider has specific instructions on where to locate these values.

  • Identity provider single sign-on URL: The authentication endpoint from your identity provider.
  • Identity provider issuer/entity ID: The unique identifier for your identity provider.
  • X.509 certificate: The security certificate used to validate SAML assertions. Copy this exactly as provided by your identity provider.

Bettermode settings

  • Create new staff: When enabled, Bettermode automatically creates a staff account for first-time SAML users who don't yet exist in your site. When disabled, only existing staff members can log in via SAML.
  • Login button text: The label displayed on the SAML authentication button on your login and sign-up pages. Leave empty to hide the button from public view.

Service Provider (SP) details

Configure the following values in your identity provider's SAML application settings:

  • Single sign-on URL: Use this Bettermode-provided value for the "Single sign-on URL," "Recipient URL," and "Destination URL" fields in your identity provider.
  • Audience restriction: If your identity provider requires audience restriction, enter this Bettermode-provided value in that field.

Related Topics

Contact Us

Do you still need help? Learn how to get in touch with the Bettermode Team.