Single sign-on (SSO)
SSO lets your team members log in to Instruqt through your company’s identity provider, instead of managing separate Instruqt credentials. SSO covers the people who build and manage labs – users who play labs through invites or embeds don’t need it.
Instruqt supports Google Workspace, Okta, and Microsoft Entra ID natively, plus any SAML 2.0 identity provider.
Configure SSO
Section titled “Configure SSO”- In the sidebar, click Settings → SSO.
- Select your identity provider. If your provider isn’t listed, contact Instruqt Support.
- A panel opens for the connection details – what goes in it depends on the provider. Follow the setup guide for yours:
Whichever provider you use, the callback URL to configure on the identity provider side is always:
https://sso.play.instruqt.com/login/callbackYour team’s login URL
Section titled “Your team’s login URL”Once SSO is configured, your team members log in through your team’s login URL, shown at the top of the SSO settings page:
https://play.instruqt.com/{team-name}/loginOpening it prompts the person to authenticate through your configured provider.
How users are provisioned
Section titled “How users are provisioned”Users are provisioned on demand: when someone logs in through SSO and no matching Instruqt account exists for their email address, an account is created and added to your team with the Member role.
Can we switch SSO providers? Yes. Instruqt uses the email address returned by the provider as the user’s identity. If the new provider returns the same email for the same person, their account carries over unchanged. Contact support if you’d like guidance or want to test the switch first.
Is de-provisioning or SCIM supported? Not at this time. If your use case requires de-provisioning, contact our support team and share your request.
