Single Sign-On Support for Enterprise Now In Beta

Posted Nov 19th, 2014

At Sauce Labs, we are hard at work identifying new ways to make adoption and usage of our products as simple and frictionless as possible. For larger organizations onboarding hundreds of users, managing access and security can quickly become challenging. To simplify the onboarding process and provide greater account security, we have rolled out integrations for four popular Single Sign-On (SSO) providers, including Ping Identity, OneLogin, Okta, and Microsoft Active Directory Federation Service (ADFS). At a high level, an SSO Identity Provider (IdP) provides a single gateway through which users can access an array of applications without logging into each application separately. A user logs into the IdP with one set of credentials and gains access to all connected applications through that same login.

This new integration reduces the likelihood that users will spend time on password recovery or account access issues and gives account owners greater control over account security. Account owners can optionally require users to log in via a corporate IdP, completely eliminating risks associated with standard account credentials.

How It Works

Our SSO support is based on the SAML 2.0 Browser POST profile. Below is a high-level representation of how authentication between the IdP and Sauce Labs is performed.

  1. User signs into the IdP via a web browser and attempts to access Sauce Labs service.
  2. IdP generates a SAML response in XML.
  3. IdP returns encoded SAML response to the browser.
  4. Browser forwards the SAML response to the Assertion Consumer Service (ACS) URL.
  5. Sauce Labs verifies the SAML response.
  6. Upon successful verification, user is granted access to Sauce Labs.


Enabling SSO For Your Account

The new SSO integrations are currently available through an open beta. If you are an Enterprise account owner and you would like to be placed in the beta, simply email us at and let us know with which provider you are interested in integrating. We will contact you to set up a kickoff and get you squared away. If you are not currently an Enterprise customer and are interested in learning about this and other Enterprise features, contact our sales team. If you have existing Sauce Labs users, we have developed a quick and painless transition process ensuring your users are able to keep their activity history and data. Once your account is enabled for SSO, your users can access Sauce Labs via the IdP. They will be presented with the option to create a new account or log into their existing account. They need only provide their existing Sauce Labs credentials and sign in. That's it - the transition process will be completed instantly and that user will be able to access Sauce Labs from the IdP in the future.

SSO Provider Partnerships

In conjunction with the release of our SSO integrations, we are pleased to announce partnerships with some of our amazing service providers. Once your account is enabled for SSO, you will be able to easily connect to your IdP through Ping Identity's Application CatalogOkta's Application Network (OAN), or OneLogin's Connector.

Further Reading

If you do not currently use a Single Sign-On service provider and are interested in learning more about our integrated services, follow the links below. Ping Identity OneLogin Okta We love talking with our users so feel free to reach out to us at with any comments, feedback, or requests.  

Written by

The Sauce Labs Team