Skip to content

SSO and SCIM

Single sign-on (SSO) is an authentication scheme that allows users to log in to Storyblok using their existing accounts from trusted third-party services.

SSO ensures secure, seamless access with a single ID managed by a specialized identity provider (IdP), which eliminates the need to create additional, per-app accounts.

Storyblok supports the following IdPs and Security Assertion Markup Language (SAML) standards:

  • Auth0
  • Google Workspace
  • JumpCloud
  • Microsoft Entra ID (OpenID)
  • Okta
  • OneLogin
  • Salesforce
  • SAML 2.0
  • SAML 1.0

In addition to SSO, Storyblok organization and space admins can use the System for Cross-domain Identity Management (SCIM) standard to reduce manual processes and keep access in sync.

As an open standard for user provisioning, SCIM automatically creates and updates users from an IdP and manages Storyblok space assignments through groups.

Storyblok acts as the server that receives the requests and supports SCIM provisioning via two IdPs: Microsoft Entra ID and Okta. These services act as the clients that send requests.

To configure SSO with Microsoft Entra ID, first contact Storyblok’s support team and provide your tenant ID and the domains you use for SSO login.

Follow Microsoft’s guide to find your Entra tenant ID.

  1. Create an enterprise application

    Follow Microsoft’s guide to add an enterprise application for Storyblok.

  2. Configure the callback URLs

    In Storyblok, open your organization’s Settings → SSO Settings, and copy the SSO Identifier.

    Back in Microsoft’s dashboard, paste the following values in the relevant fields—replace YOUR-SSO-IDENTIFIER with your actual SSO Identifier:

    Field name Value
    Identifier (Entity ID) https://mapi.storyblok.com/saml/metadata?connection=YOUR-SSO-IDENTIFIER
    Reply URL (Assertion Consumer Service URL) https://mapi.storyblok.com/saml/consume?connection=YOUR-SSO-IDENTIFIER
  3. Verify the SSO setup in Storyblok

    Once you’re done, open Storyblok and confirm that Sign in via SSO appears for users who access one of the configured domains.

To enable SCIM provisioning for your organization, contact Storyblok’s support team.

  1. Configure automatic user provisioning

    Follow Microsoft’s guide to configure automatic user provisioning.

    Find the Tenant URL and Secret Token in your Storyblok organization. Open Settings → SSO & Provisioning. Copy the SCIM Base URL and paste it into the Tenant URL field in Microsoft Entra ID. Generate the SCIM token and paste it into the Secret Token field.

  2. Manage users and groups in Microsoft Entra ID

    To assign and unassign users of an enterprise application in Microsoft Entra ID, follow Microsoft’s guide on assigning users and groups to an application.

    To assign users to a group, follow Microsoft’s guide on how to Manage Microsoft Entra groups and group membership.

  3. Map Storyblok space roles to Microsoft Entra ID groups

    In Storyblok, open your organization’s Settings → SSO & Provisioning → SCIM Groups section to find the External ID of the Microsoft Entra ID groups you configured for your organization.

    In your Storyblok space, open Settings → Roles and select the relevant role. Then, enable This role is for integration with SSO, and provide the External ID (used for SSO).

  4. Start provisioning

    In Microsoft Entra ID, open Enterprise Applications → Your_Enterprise_Application → Provisioning and select Start provisioning. Microsoft Entra ID starts an initial provisioning cycle and then continues with automatic incremental synchronization. For details, visit Microsoft’s guide on checking the status of user provisioning.

  5. Verify the SCIM provisioning setup in Storyblok

    Finally, to verify the SCIM provisioning in Storyblok, check that the assigned users who accepted the invite to the Storyblok space appear in this format: user-scim-externalid|scim|{org_id}|@yourdomain.com.

To verify that Microsoft Entra ID correctly revokes user access in Storyblok, follow the steps below:

  1. Disable a user or remove them from the enterprise application in Microsoft Entra ID.
  2. Select Start provisioning.
  3. Wait for the synchronization cycle to complete.
  4. Confirm that Storyblok disables the user in the organization.

To configure SSO with Okta, first contact Storyblok’s support team and provide your IdP metadata (an XML file) and the domains you use for SSO login.

  1. Create the Storyblok application in Okta

    Follow Okta’s guide to create SAML app integrations.

  2. Configure the callback URLs

    In Storyblok, open your organization’s Settings → SSO Settings, and copy the SSO Identifier. Back in Okta, paste the following values in the relevant fields—replace YOUR-SSO-IDENTIFIER with your actual SSO Identifier:

    Field name Value
    Audience URI (SP Entity ID) https://mapi.storyblok.com/saml/metadata?connection=YOUR-SSO-IDENTIFIER
    Single sign-on URL https://mapi.storyblok.com/saml/consume?connection=YOUR-SSO-IDENTIFIER
    Name ID format EmailAddress
    Application username Email
  3. Define attribute statements

    Follow Okta’s Define attribute statements guide to create profile attribute statements:

    Attribute name Name format Value Description
    givenname Unspecified user.firstName User’s first name
    surname Unspecified user.lastName User’s last name
    email Unspecified user.email User’s primary email address

    In Storyblok, open your organization’s Settings → SSO Settings → Attribute mapping section, and add the matching attribute names. The values must be identical.

  4. Map Storyblok space roles to Okta groups

    You can manage space roles assignments using either SCIM provisioning (recommended) or SAML group attribute.

    SCIM provisioning

    When you enable SCIM for your organization, Okta automatically manages user assignments to space roles when you add or remove users from a group. Don’t include a group attribute statement in the Okta SAML app.

    SAML group attribute

    Follow Okta’s Define Group attribute statements guide and include the groupid attribute in the SAML assertion, as shown below:

    Attribute name Name format Description
    groupid Unspecified Identifier for the user’s groups (roles)

    In your Storyblok space, open Settings → Roles and select the relevant role. Then, enable This role is for integration with SSO. In the External ID (used for SSO) field, enter the exact value that your IdP sends in the groupid attribute.

  5. Verify the SSO setup in Storyblok

    Once you’re done, open Storyblok and confirm that Sign in via SSO appears for users who access one of the configured domains.

To enable SCIM provisioning for your organization, contact Storyblok’s support team.

  1. Configure automatic user provisioning

    Follow Okta’s guide to add SCIM provisioning.

    In Storyblok, open your organization’s Settings → SSO & Provisioning. Copy the SCIM Base URL and paste it into the SCIM connector base URL field in Okta. Generate a SCIM token in Storyblok. In Okta, select HTTP Header as the authentication mode and paste the token into the Authorization field.

    Storyblok supports all provisioning actions.

  2. Manage users and groups in Okta

    Follow Okta’s guide and create a user. Next, assign the user to the Storyblok app. Then, create a group, and assign the user to the group.

  3. Map Storyblok space roles to Okta groups

    In Storyblok, open your organization’s Settings → SSO & Provisioning → SCIM Groups section to find the External ID of the Okta groups you configured for your organization.

    In your Storyblok space, open Settings → Roles and select the relevant role. Then, enable This role is for integration with SSO, and provide the External ID (used for SSO).

  4. Verify the SCIM provisioning setup in Storyblok

    Finally, to verify the SCIM provisioning in Storyblok, check that the assigned users who accepted the invite to the Storyblok space appear in this format: user-scim-externalid|scim|{org_id}|@yourdomain.com.

To verify that Okta correctly revokes user access in Storyblok, unassign the user from the Storyblok app in Okta. Storyblok automatically disables the user in your organization.

Was this page helpful?

What went wrong?

This site uses reCAPTCHA and Google's Privacy Policy (opens in a new window).Terms of Service (opens in a new window) apply.