Skip to content

You are viewing documentation for Instruqt 2.0 Labs which is in Beta currently. Official release date - 29 September, 2026. For Tracks documentation, please visit docs.instruqt.com.

Single sign-on (SSO)


SSO lets your team members log in to Instruqt through your company’s identity provider, instead of managing separate Instruqt credentials. SSO covers the people who build and manage labs – users who play labs through invites or embeds don’t need it.

Instruqt supports Google Workspace, Okta, and Microsoft Entra ID natively, plus any SAML 2.0 identity provider.

  1. In the sidebar, click SettingsSSO.
  2. Select your identity provider. If your provider isn’t listed, contact Instruqt Support.
  3. A panel opens for the connection details – what goes in it depends on the provider. Follow the setup guide for yours:

Whichever provider you use, the callback URL to configure on the identity provider side is always:

https://sso.play.instruqt.com/login/callback

Once SSO is configured, your team members log in through your team’s login URL, shown at the top of the SSO settings page:

https://play.instruqt.com/{team-name}/login

Opening it prompts the person to authenticate through your configured provider.

Users are provisioned on demand: when someone logs in through SSO and no matching Instruqt account exists for their email address, an account is created and added to your team with the Member role.

Can we switch SSO providers? Yes. Instruqt uses the email address returned by the provider as the user’s identity. If the new provider returns the same email for the same person, their account carries over unchanged. Contact support if you’d like guidance or want to test the switch first.

Is de-provisioning or SCIM supported? Not at this time. If your use case requires de-provisioning, contact our support team and share your request.