Skip to main content

Integrate with an identity provider and log in with SAML SSO

Configure SAML SSO to let your team log in to Intercom using your identity provider like Okta or OneLogin.

Written by Eric Fitzgerald

Use this article to set up SAML Single Sign-On (SSO) for your Intercom workspace. It covers enabling SAML in Intercom, configuring your identity provider (IdP), verifying your domain, testing and enforcing SSO, enabling Just-in-Time (JIT) provisioning, and step-by-step setup guides for OneLogin and Okta.

Once configured, SAML SSO will also work with the Intercom Conversations app on iOS and Android.


Before you start

Important:

  • SAML SSO is only available on Expert Intercom plan. Check our plans and pricing to learn more about this plan.

  • You must have permissions to access Settings > Workspace > Security in Intercom, as well as administrative access to your identity provider.


Step 1: Enable SAML SSO in Intercom

First, you need to enable SAML SSO in your Intercom workspace to get the URLs for your identity provider.

  1. Toggle on SAML SSO.

    Screenshot of the Authentication methods section in Settings > Workspace > Security, showing the SAML SSO toggle being switched on
  2. Once toggled on, the SAML SSO configuration section will appear.

    Screenshot showing the SAML SSO configuration section that appears after enabling the toggle, with fields for Identity Provider Single Sign-On URL and Public certificate
  3. The first thing you’ll see is the unique SAML URL for your workspace. Keep this page open; you will need this URL for the next step.

    Screenshot of the SAML SSO settings showing the unique SAML URL for the workspace, used to configure the identity provider

Step 2: Configure your identity provider

In your identity provider's settings (like Okta or OneLogin), you will need to add Intercom as an application. You will need the SAML URL from Step 1.

Use the following parameters in your IdP's configuration:

  • Single Sign-On URL: <SAML URL>/consume

  • Recipient URL: <SAML URL>/consume

  • Audience restriction/Entity ID: <SAML URL>

  • NameID: Email address

  • Signed Assertions: Yes

  • Mapped Attributes:

    • firstName (User's first name)

    • lastName (User's last name)

  • Encryption: Use AES256_CBC encryption and provide Intercom's certificate (shown below) in your IdP's encryption settings:

-----BEGIN CERTIFICATE-----
MIIDYzCCAkugAwIBAgIUS9LFUH5IWanIgQ78d/qyKOdojAYwDQYJKoZIhvcNAQEL
BQAwQTERMA8GA1UECgwISW50ZXJjb20xETAPBgNVBAsMCFBsYXRmb3JtMRkwFwYD
VQQDDBBTQU1MIENlcnRpZmljYXRlMB4XDTI2MDExMjE3NTIzN1oXDTM2MDExMDE3
NTIzN1owQTERMA8GA1UECgwISW50ZXJjb20xETAPBgNVBAsMCFBsYXRmb3JtMRkw
FwYDVQQDDBBTQU1MIENlcnRpZmljYXRlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
MIIBCgKCAQEA2LVcYLNwR0t1Co/FBNSFUEdpOJTM87X0//NPisUgQJ71l11Dohg9
Yg1aAraqOsQ9EPR9prdQjP50lhOmogjvPDClPlXtoHdRCJ81U/3duXoBdGS02NN3
2DetudNnyjeUefkcnPWsQ+FNZasnP9ODU8dtPKxMcLP3AmcUYOAaKp1r3WBuFDcT
woMtbrWUoxTfBeYx6nQ9TfzJOGQFZCYs30Sx1j5LVio5DoM3oynTTh0qOzJS+KpU
iIIqby8szpqWMfdPNTdBd7XQK2SkHmBgkgSDfQIII93kkXCP1bCOuo4rC+lIeXlF
gIi2Z4iMxuKceBeLBgFTovG7dVDeGmTucQIDAQABo1MwUTAdBgNVHQ4EFgQUgZdt
wisFHetsCww03EXQGt8Oq24wHwYDVR0jBBgwFoAUgZdtwisFHetsCww03EXQGt8O
q24wDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAQEAiL3wXWof5x+k
thOn2tAspFR/IH5NQHPLocV605FcRjt1JS1z0cBjtBroTKFarXo6T1NKQN5Lhjsu
wrvu1J/YQcGnSmChar8OJSIbxPhHrbpA6Gg2mtkH4BTnnXY3LBgVFfCl5oiFxZqB
ELkm6iBZmReot+MPWvE0Ypx7hQLI/3qLc5yYEw7ZNKWq/lRbbT4DLgKeHH89fSrm
cpDa9ZHF2e6rlx95LCbZUWyEE6pPFeq+6CyQt+FkwLl1e+ZIJTknWgD/bzPsZ6CF
XfF2fS2ObaUISKYEZMZx5o+JZnnYGr1U614lhniha+Rpykzoa+SsOdwvI0xl5ZRr
aqD3fI3jqA==
-----END CERTIFICATE-----

Note: If your identity provider supports it, you can define a session duration in your IdP's configuration. This sets the length of time before a teammate's session expires and they must log in to Intercom again. If this is not set, the default duration is 3.5 days.


Step 3: Configure Intercom with your IdP's details

After configuring your IdP, you must add its details back into Intercom.

  1. Return to your Intercom SAML SSO settings page (Settings > Workspace > Security).

  2. Add the following information from your identity provider:

    • Identity provider Single Sign-On URL: This is the URL used to start the login process.

    • Public certificate: This allows Intercom to validate SAML requests from your IdP. Paste the full X.509 certificate (a standard digital certificate format) from your identity provider.

      Screenshot of the SAML SSO settings in Intercom showing the Identity provider Single Sign-On URL field and the Public certificate field where the X.509 certificate is pasted


Step 4: Add and verify your allowed domains

You must specify which domains are allowed to authenticate with SAML SSO.

  1. Enter a domain under "Allowed domains" and click Add domain.

    Screenshot of the Allowed domains section in SAML SSO settings showing a domain input field and the Add domain button

  2. You must verify that you own the domain by adding a TXT record in your DNS settings with the provided values.

    Screenshot showing the DNS verification section with the TXT record name and value that must be added to the domain's DNS settings

  3. After adding the TXT record, click Verify DNS record.

    Screenshot of the Allowed domains section showing the Verify DNS record button next to an unverified domain

  4. Once verified, you’ll see a success message and the domain will be added. Repeat this process if you need to add more than one domain.

    Screenshot showing a successfully verified domain in the Allowed domains section with a green success confirmation message

Note: If you have just created the DNS record, it may still be propagating. If you see a warning message ("Unable to verify DNS record. Please try again later."), wait a few minutes and try again. DNS changes can take up to 48 hours to propagate fully.

To uncheck this option and enforce SAML SSO as the required login method, you must be logged in with SAML SSO. You can do this after saving your settings.


Step 5: Test and enforce SAML SSO

Before enforcing SAML for all teammates, you must test the configuration.

  1. Test your setup: To ensure all teammates can log in successfully with SAML SSO before disabling other methods, leave the Google Sign-On and Email and password options toggled on.

    Screenshot of the Authentication methods section in SAML SSO settings showing the Google Sign-On and Email and password toggles left enabled during testing to ensure all teammates can log in before other methods are disabled
  2. Save your settings at the bottom of the page.

  3. Log out and attempt to log back in using the Sign in with SAML SSO option to test your configuration.

    Screenshot of the Intercom login page showing the Sign in with SAML SSO button below the standard email and password fields

  4. Enforce SAML SSO (Optional): Once you have successfully logged in and confirmed the setup works, you can return to the settings and uncheck the other login methods.

Note:

  • To uncheck the other login options and enforce SAML SSO as the only login method, you must be logged in with SAML SSO yourself.

  • Once your workspace has SAML SSO enabled, teammates will be unable to edit their own email address from their Account security page. The email field will be read-only.

  • [{type: "paragraph", text: "Before removing other login methods, ensure all teammates have tested and confirmed SAML login. Any teammate who hasn't authenticated with SAML yet will be locked out immediately when other methods are disabled."}]

  • [{type: "paragraph", text: "Existing teammates are not automatically migrated to SAML — they continue to use their current login method until you disable it. Notify your team before enforcing SAML-only login."}]


How SAML SSO works for your team

How teammates log in

Once SAML SSO is enabled, teammates will see a Sign in with SAML SSO button on the login page. The login experience will vary based on their email address:

  • Email not registered: If the email entered doesn't match a teammate in a workspace with SAML enabled, they will see an error message.

  • Email registered for one SAML workspace: The teammate is redirected to the identity provider to log in.

    Screenshot of the SAML SSO login page showing an email input field where teammates enter their work email to be redirected to their identity provider
  • Email registered for multiple SAML workspaces: The teammate is shown the workspace selector. After selecting a workspace, they are redirected to the correct identity provider for that workspace.

    Screenshot of the workspace selector screen shown when a teammate's email is registered across multiple workspaces with SAML SSO enabled, listing available workspaces to choose from

Depending on the identity provider the teammate has for each workspace, the teammate is redirected to the right identity provider's login experience. After performing the log in, the user is brought back to the correct workspace and logged in.

Switching between workspaces

SAML SSO is supported when switching between workspaces. The workspace switcher (shown below) lets you move between workspaces using different authentication methods — if you're already logged in with the same SAML provider, no re-authentication is required:

Screenshot of the workspace switcher interface showing multiple workspaces, used when switching between workspaces that use different authentication methods
  • If a teammate is logged into two workspaces that use the same SAML SSO provider, they can switch between them without needing to re-authenticate.

  • If the teammate has access to a third workspace that uses email/password, and they aren't logged in, they will be redirected to the workspace switcher to log in with their password.

Logging in on the mobile app (Intercom Conversations app)

SAML SSO is supported on the iOS and Android Intercom Conversations app.

  1. Navigate to the log in screen and tap the Sign in with SAML SSO button.

    Screenshot of the Intercom Conversations mobile app login screen showing the Sign in with SAML SSO button
  2. Enter your work email and tap Continue.

    Screenshot of the Intercom Conversations mobile app showing the email input screen where teammates enter their work email to continue with SAML SSO login
  3. If you have access to multiple workspaces, you will see a list to choose from. (If you only have one, this screen is skipped).

  4. Selecting a workspace will open a web view to log in to your SAML provider.

  5. Once you sign in, you will be logged into the app.

If you don’t have SAML SSO set up for your account and try to log in with SAML SSO, you'll see an error message.

Workspace invites

When SAML SSO is enabled on your workspace, it's compatible with workspace invites. The invite email must match the email address returned by your identity provider — if they don't match, the invite redemption will fail.

How to change teammate email addresses when SAML SSO is enabled

  1. Enable Email and password as a login method in Settings > Workspace > Security, if not already enabled.

  2. All teammates set or reset their Intercom password and confirm they can log in with their old email and password.

  3. Disable SAML SSO on the workspace — this makes the email field editable for teammates.

  4. Each teammate logs in with their old email and password, then updates their own login email to the new domain.

  5. Update all teammate emails in your identity provider to the new domain.

  6. Re-enable SAML SSO on the workspace.

  7. SAML SSO now works with the new email addresses. Optionally re-enforce SSO-only login.


How to set up and troubleshoot SAML SSO with specific identity providers

Need help with your identity provider? Intercom Support can help you configure SAML SSO within Intercom. For IdP-specific setup steps, configuration within your provider's admin console (e.g. Microsoft Entra, Okta, JumpCloud), or errors originating from your IdP, we recommend contacting your identity provider's support team directly — they'll have access to your environment and can resolve issues on their side. Our SAML documentation is available to share with them as a reference.

Troubleshooting Google Workspace

If you are using Google Workspace as your SSO provider and see an access error, you can turn on "remediation messages" in your Google Admin console to understand the reason for the error. Once enabled, you'll see more detailed information in the error message (e.g., "the device... is not managed by Google endpoint management").

Screenshot of the Google Admin console showing the remediation messages setting that can be enabled to display more detailed SSO error information

Once enabled, you'll be able to see more detailed information in the error message.

For example, the following error could indicate that the device which is being used is not managed by Google endpoint management:

Screenshot showing a detailed Google Workspace SSO error message indicating the device is not managed by Google endpoint management


How to enable Just-in-Time (JIT) provisioning

Just-in-Time provisioning will automatically add teammates to your Intercom workspace the first time they sign in with SAML SSO, if they don’t already have an Intercom account.

To enable this, go to Settings > Workspace > Security, make sure SAML SSO is toggled on, and click on Provisioning:

Screenshot of the SAML SSO settings page showing the Provisioning section with the Just-in-Time provisioning option available to enable

Then, define which permissions new teammates should have when added by JIT provisioning:

Screenshot of the Just-in-Time provisioning settings showing the default permissions configuration for new teammates automatically added via JIT

Note: New teammates will only be added if you have available seats.

Finally, save your settings, then test your setup by logging out and signing in with your identity provider. You should be redirected back to your Intercom workspace after successful authentication:

Screenshot of the SAML SSO settings page showing the Save button and the test authentication prompt after completing JIT provisioning setup

Once your workspace has SAML SSO enabled with any provider, teammates will be unable to edit their own email address from their Account security page. The email field will be read-only.

Screenshot of the Account security page showing the email address field as read-only and greyed out when SAML SSO is enabled for the workspace


Configuring SAML with OneLogin

You can use the "Intercom SAML 2.0" app in the OneLogin store.

  1. In your OneLogin admin page, go to Applications and click Add App.

    Screenshot of the OneLogin admin dashboard Applications page showing the Add App button used to add a new application

  2. Search for and add the Intercom SAML 2.0 app.

    Screenshot of the OneLogin app search results showing the Intercom SAML 2.0 application in the results list

  3. Open the Configuration tab and enter the SAML name for your workspace.

    Screenshot of the OneLogin Intercom app Configuration tab showing the SAML name field where the workspace SAML name is entered

  4. On the SSO tab, copy the "SAML 2.0 Endpoint" URL and paste it into your Intercom workspace's SAML settings.

    Screenshot of the OneLogin Intercom app SSO tab showing the SAML 2.0 Endpoint URL that must be copied into Intercom's SAML settings

  5. Click View Details under the certificate, copy the certificate, and paste it into Intercom's Public certificate field.

    Screenshot of the OneLogin certificate View Details screen showing the certificate to be copied and pasted into Intercom's Public certificate field

  6. Save your settings in Intercom and test the connection.

Note: If your workspace is hosted in the EU or AU, reach out to the OneLogin team to make sure your integration is supported.


Configuring SAML with Okta

You can use the "Intercom" app from the Okta App Store.

  1. In Okta:

    • Open the Okta admin dashboard and add the Intercom app.

    • Proceed to the Sign-On Options.

    • Download the Signing Certificate and copy the Sign on URL provided by Okta.

      Screenshot of the Okta Intercom app Sign-On Options tab showing the Signing Certificate download button and the Sign on URL to be copied into Intercom's SAML settings
  2. In Intercom:

    • Go to Settings > Workspace > Security and toggle on SAML SSO.

    • Make note of your SAML URL (at the top of the SAML settings).

    • Enter the following details from Okta:

      • Identity Provider Sign-On URL: (The Sign on URL from Okta)

      • Public Certificate: (Paste the full certificate downloaded from Okta)

    • Under "Allowed Domains", enter your company’s domain (e.g., acme.com).

    • Do not click Save yet.

  3. Back in Okta:

    • Return to your Okta Intercom app's Sign-On Options.

    • Under Encryption Certificate, upload the following certificate as intercom.pem:

      -----BEGIN CERTIFICATE-----
      MIIDYzCCAkugAwIBAgIUS9LFUH5IWanIgQ78d/qyKOdojAYwDQYJKoZIhvcNAQEL
      BQAwQTERMA8GA1UECgwISW50ZXJjb20xETAPBgNVBAsMCFBsYXRmb3JtMRkwFwYD
      VQQDDBBTQU1MIENlcnRpZmljYXRlMB4XDTI2MDExMjE3NTIzN1oXDTM2MDExMDE3
      NTIzN1owQTERMA8GA1UECgwISW50ZXJjb20xETAPBgNVBAsMCFBsYXRmb3JtMRkw
      FwYDVQQDDBBTQU1MIENlcnRpZmljYXRlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A
      MIIBCgKCAQEA2LVcYLNwR0t1Co/FBNSFUEdpOJTM87X0//NPisUgQJ71l11Dohg9
      Yg1aAraqOsQ9EPR9prdQjP50lhOmogjvPDClPlXtoHdRCJ81U/3duXoBdGS02NN3
      2DetudNnyjeUefkcnPWsQ+FNZasnP9ODU8dtPKxMcLP3AmcUYOAaKp1r3WBuFDcT
      woMtbrWUoxTfBeYx6nQ9TfzJOGQFZCYs30Sx1j5LVio5DoM3oynTTh0qOzJS+KpU
      iIIqby8szpqWMfdPNTdBd7XQK2SkHmBgkgSDfQIII93kkXCP1bCOuo4rC+lIeXlF
      gIi2Z4iMxuKceBeLBgFTovG7dVDeGmTucQIDAQABo1MwUTAdBgNVHQ4EFgQUgZdt
      wisFHetsCww03EXQGt8Oq24wHwYDVR0jBBgwFoAUgZdtwisFHetsCww03EXQGt8O
      q24wDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAQEAiL3wXWof5x+k
      thOn2tAspFR/IH5NQHPLocV605FcRjt1JS1z0cBjtBroTKFarXo6T1NKQN5Lhjsu
      wrvu1J/YQcGnSmChar8OJSIbxPhHrbpA6Gg2mtkH4BTnnXY3LBgVFfCl5oiFxZqB
      ELkm6iBZmReot+MPWvE0Ypx7hQLI/3qLc5yYEw7ZNKWq/lRbbT4DLgKeHH89fSrm
      cpDa9ZHF2e6rlx95LCbZUWyEE6pPFeq+6CyQt+FkwLl1e+ZIJTknWgD/bzPsZ6CF
      XfF2fS2ObaUISKYEZMZx5o+JZnnYGr1U614lhniha+Rpykzoa+SsOdwvI0xl5ZRr
      aqD3fI3jqA==
      -----END CERTIFICATE-----

    • Under "Advanced Sign-On Settings", paste your SAML Base URL from Intercom.

    • Click Save.

  4. Test and Activate:

    • Go back to your Intercom workspace's SAML settings and click Save.

    • Test your SAML configuration by logging out and logging back in with SAML.

    • Once confirmed, you can return to settings and uncheck the email/password or Google sign-on options to enforce SAML.


💡Tip

Need more help? Get support from our Community Forum
Find answers and get help from Intercom Support and Community Experts


Did this answer your question?