kimo
Docs

SSO & SCIM

Configure SAML or OIDC single sign-on and SCIM provisioning with Okta, Microsoft Entra ID or Google Workspace, and map groups to Kimo roles and spaces.

Updated Sep 29, 20266 min readEdit on GitHub

Single sign-on lets your team log in with your identity provider, and SCIM keeps users and groups in sync automatically. Both are available on Business and Enterprise plans, and in every on-premise deployment. Read more about our approach on the security page.

Supported providers

ProviderSSOSCIMGroup sync
OktaSAML 2.0, OIDCYesYes
Microsoft Entra IDSAML 2.0, OIDCYesYes
Google WorkspaceSAML 2.0Via directory syncYes
KeycloakSAML 2.0, OIDCYesYes
Any SAML 2.0 IdPSAML 2.0SCIM 2.0Yes

Configure SAML

  1. 1
    Verify your domain

    In Settings → Security → Domains, add a TXT record to prove you own example.com. Only verified domains can enforce SSO.

  2. 2
    Create an app in your IdP

    Use the ACS URL and Entity ID shown in Kimo. Set the NameID format to email address.

  3. 3
    Upload IdP metadata

    Paste the metadata URL or upload the XML. Kimo validates the certificate and shows its expiry date.

  4. 4
    Test, then enforce

    Log in from a private window with Test SSO. Once it works, enable Require SSO; password logins are disabled except for break-glass admins.

Service provider values
ACS URL     https://auth.getkimo.com/saml/acme/acsEntity ID   https://auth.getkimo.com/saml/acmeNameID      emailAddressAttributes  email, firstName, lastName, groups

SCIM provisioning

Generate a SCIM token under Settings → Security → SCIM and paste it into your IdP with the base URL below. Users created in the IdP are provisioned on first assignment; deactivated users lose access within a minute and their sessions are revoked.

cURL
curl https://api.getkimo.com/scim/v2/Users?filter=userName%20eq%20%[email protected]%22 \  -H "Authorization: Bearer $KIMO_SCIM_TOKEN"

Mapping groups to roles

IdP groupKimo roleSpaces
kimo-adminsAdminAll
financeEditorFinance
growthEditorGrowth, Web
everyoneViewerCompany

Sessions and MFA

When SSO is enforced, session length and MFA are controlled by your identity provider. Kimo adds its own guardrails on top: sessions expire after 12 hours of inactivity by default (configurable from 1 to 72 hours), and sensitive actions such as creating API tokens, changing SSO settings or exporting more than 100,000 rows require a fresh login within the last 15 minutes.

  • Restrict access to corporate networks with an IP allowlist (Enterprise).
  • Every login, role change and token creation is written to the audit log and can be streamed to your SIEM.
  • Break-glass logins trigger an email to all admins.