SSO and SCIM
Single sign-on (SSO) is an authentication scheme that allows users to log in to Storyblok using their existing accounts from trusted third-party services.
SSO ensures secure, seamless access with a single ID managed by a specialized identity provider (IdP), which eliminates the need to create additional, per-app accounts.
SSO providers
Section titled “SSO providers”Storyblok supports the following IdPs and Security Assertion Markup Language (SAML) standards:
Identity providers
Section titled “Identity providers”- Auth0
- Google Workspace
- JumpCloud
- Microsoft Entra ID (OpenID)
- Okta
- OneLogin
- Salesforce
SAML standards
Section titled “SAML standards”- SAML 2.0
- SAML 1.0
What is SCIM
Section titled “What is SCIM”In addition to SSO, Storyblok organization and space admins can use the System for Cross-domain Identity Management (SCIM) standard to reduce manual processes and keep access in sync.
As an open standard for user provisioning, SCIM automatically creates and updates users from an IdP and manages Storyblok space assignments through groups.
Storyblok acts as the server that receives the requests and supports SCIM provisioning via two IdPs: Microsoft Entra ID and Okta. These services act as the clients that send requests.
Set up SSO with Microsoft Entra ID
Section titled “Set up SSO with Microsoft Entra ID”To configure SSO with Microsoft Entra ID, first contact Storyblok’s support team and provide your tenant ID and the domains you use for SSO login.
Follow Microsoft’s guide to find your Entra tenant ID.
-
Create an enterprise application
Follow Microsoft’s guide to add an enterprise application for Storyblok.
-
Configure the callback URLs
In Storyblok, open your organization’s Settings → SSO Settings, and copy the SSO Identifier.
Back in Microsoft’s dashboard, paste the following values in the relevant fields—replace
YOUR-SSO-IDENTIFIERwith your actual SSO Identifier:Field name Value Identifier (Entity ID) https://mapi.storyblok.com/saml/metadata?connection=YOUR-SSO-IDENTIFIERReply URL (Assertion Consumer Service URL) https://mapi.storyblok.com/saml/consume?connection=YOUR-SSO-IDENTIFIER -
Verify the SSO setup in Storyblok
Once you’re done, open Storyblok and confirm that Sign in via SSO appears for users who access one of the configured domains.
Provision SCIM on Microsoft Entra ID
Section titled “Provision SCIM on Microsoft Entra ID”To enable SCIM provisioning for your organization, contact Storyblok’s support team.
-
Configure automatic user provisioning
Follow Microsoft’s guide to configure automatic user provisioning.
Find the Tenant URL and Secret Token in your Storyblok organization. Open Settings → SSO & Provisioning. Copy the SCIM Base URL and paste it into the Tenant URL field in Microsoft Entra ID. Generate the SCIM token and paste it into the Secret Token field.
-
Manage users and groups in Microsoft Entra ID
To assign and unassign users of an enterprise application in Microsoft Entra ID, follow Microsoft’s guide on assigning users and groups to an application.
To assign users to a group, follow Microsoft’s guide on how to Manage Microsoft Entra groups and group membership.
-
Map Storyblok space roles to Microsoft Entra ID groups
In Storyblok, open your organization’s Settings → SSO & Provisioning → SCIM Groups section to find the External ID of the Microsoft Entra ID groups you configured for your organization.
In your Storyblok space, open Settings → Roles and select the relevant role. Then, enable This role is for integration with SSO, and provide the External ID (used for SSO).
-
Start provisioning
In Microsoft Entra ID, open Enterprise Applications →
Your_Enterprise_Application→ Provisioning and select Start provisioning. Microsoft Entra ID starts an initial provisioning cycle and then continues with automatic incremental synchronization. For details, visit Microsoft’s guide on checking the status of user provisioning. -
Verify the SCIM provisioning setup in Storyblok
Finally, to verify the SCIM provisioning in Storyblok, check that the assigned users who accepted the invite to the Storyblok space appear in this format:
user-scim-externalid|scim|{org_id}|@yourdomain.com.
Revoke user access
Section titled “Revoke user access”To verify that Microsoft Entra ID correctly revokes user access in Storyblok, follow the steps below:
- Disable a user or remove them from the enterprise application in Microsoft Entra ID.
- Select Start provisioning.
- Wait for the synchronization cycle to complete.
- Confirm that Storyblok disables the user in the organization.
Set up SSO with Okta
Section titled “Set up SSO with Okta”To configure SSO with Okta, first contact Storyblok’s support team and provide your IdP metadata (an XML file) and the domains you use for SSO login.
-
Create the Storyblok application in Okta
Follow Okta’s guide to create SAML app integrations.
-
Configure the callback URLs
In Storyblok, open your organization’s Settings → SSO Settings, and copy the SSO Identifier. Back in Okta, paste the following values in the relevant fields—replace
YOUR-SSO-IDENTIFIERwith your actual SSO Identifier:Field name Value Audience URI (SP Entity ID) https://mapi.storyblok.com/saml/metadata?connection=YOUR-SSO-IDENTIFIERSingle sign-on URL https://mapi.storyblok.com/saml/consume?connection=YOUR-SSO-IDENTIFIERName ID format EmailAddressApplication username Email -
Define attribute statements
Follow Okta’s Define attribute statements guide to create profile attribute statements:
Attribute name Name format Value Description givennameUnspecified user.firstNameUser’s first name surnameUnspecified user.lastNameUser’s last name emailUnspecified user.emailUser’s primary email address In Storyblok, open your organization’s Settings → SSO Settings → Attribute mapping section, and add the matching attribute names. The values must be identical.
-
Map Storyblok space roles to Okta groups
You can manage space roles assignments using either SCIM provisioning (recommended) or SAML group attribute.
SCIM provisioning
When you enable SCIM for your organization, Okta automatically manages user assignments to space roles when you add or remove users from a group. Don’t include a group attribute statement in the Okta SAML app.
SAML group attribute
Follow Okta’s Define Group attribute statements guide and include the
groupidattribute in the SAML assertion, as shown below:Attribute name Name format Description groupidUnspecified Identifier for the user’s groups (roles) In your Storyblok space, open Settings → Roles and select the relevant role. Then, enable This role is for integration with SSO. In the External ID (used for SSO) field, enter the exact value that your IdP sends in the
groupidattribute. -
Verify the SSO setup in Storyblok
Once you’re done, open Storyblok and confirm that Sign in via SSO appears for users who access one of the configured domains.
Provision SCIM on Okta
Section titled “Provision SCIM on Okta”To enable SCIM provisioning for your organization, contact Storyblok’s support team.
-
Configure automatic user provisioning
Follow Okta’s guide to add SCIM provisioning.
In Storyblok, open your organization’s Settings → SSO & Provisioning. Copy the SCIM Base URL and paste it into the SCIM connector base URL field in Okta. Generate a SCIM token in Storyblok. In Okta, select HTTP Header as the authentication mode and paste the token into the Authorization field.
Storyblok supports all provisioning actions.
-
Manage users and groups in Okta
Follow Okta’s guide and create a user. Next, assign the user to the Storyblok app. Then, create a group, and assign the user to the group.
-
Map Storyblok space roles to Okta groups
In Storyblok, open your organization’s Settings → SSO & Provisioning → SCIM Groups section to find the External ID of the Okta groups you configured for your organization.
In your Storyblok space, open Settings → Roles and select the relevant role. Then, enable This role is for integration with SSO, and provide the External ID (used for SSO).
-
Verify the SCIM provisioning setup in Storyblok
Finally, to verify the SCIM provisioning in Storyblok, check that the assigned users who accepted the invite to the Storyblok space appear in this format:
user-scim-externalid|scim|{org_id}|@yourdomain.com.
Revoke user access
Section titled “Revoke user access”To verify that Okta correctly revokes user access in Storyblok, unassign the user from the Storyblok app in Okta. Storyblok automatically disables the user in your organization.
Was this page helpful?
This site uses reCAPTCHA and Google's Privacy Policy (opens in a new window).Terms of Service (opens in a new window) apply.
Get in touch with the Storyblok community