> For the complete documentation index, see [llms.txt](https://docs.snyk.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.snyk.io/scan-fix-and-prevent/scan-with-snyk/snyk-api-web/managing-account/set-up-single-sign-on-sso-in-snyk-api-web.md).

# Set up single sign-on (SSO)

How to set up single sign-on (SSO) in Snyk API and Web

Learn how to configure your company's Single Sign-On to log in to the Snyk API & Web app.

Snyk API & Web uses the standard Security Assertion Markup Language (SAML) to exchange authentication and authorization information with an Identity Provider (IdP) to enable Single Sign-On (SSO) to the Snyk API & Web app. This means that if you have your company's SSO in place for your users to log in to your applications, you can also enable SSO to access the Snyk API & Web app.

When you do this, users from your account can choose the following option from the login screen to access Snyk API & Web:

Note:

* If you already use SSO to log in to Snyk, you can log in to Snyk API & Web with your existing Snyk account, using the **Log in with Snyk** button:
* If you already have a Snyk account but you do not use SSO, you can [set up SSO with Snyk](https://docs.snyk.io/enterprise-setup/single-sign-on-sso-for-authentication-to-snyk).

Learn more in [Log in to Snyk API & Web](/scan-fix-and-prevent/scan-with-snyk/snyk-api-web/managing-account/log-in-to-snyk-api-web.md).

***

The configuration of the SSO specific to Snyk API & Web involves two steps:

1. Configure Snyk API & Web in your Identity Provider.
2. Configure SSO in Snyk API & Web.

This article describes these steps in detail.

After you complete this setup, you can choose the following option from the login screen to access your account:

## Step 1: Configure Snyk API & Web in your Identity Provider

In this first step, navigate to your Identity Provider and create an entry for Snyk API & Web using the following information:

* **Entity Identifier** - The URL that identifies Snyk API & Web as the issuer of SAML requests, responses, or assertions: `https://probely.com`.
* **Assertion Consumer Service** - The Snyk API & Web endpoint to do the SAML authentication and authorization: `https://sso.plus.probely.app/sso/<organization-id>/complete/`

In the endpoint, replace `<organization-id>` with a string that identifies your organization, using lowercase letters and hyphens only. For example, use the company name. If you need help, Snyk can suggest it for you.

* **Certificate** - The SAML certificate for Snyk API & Web:

```
MIIFjzCCA3egAwIBAgIUBjrMlHlE8dKutYm0cz0JXFIjMMQwDQYJKoZIhvcNAQELBQAwVzELMAkGA1UEBhMCUFQxDzANBgNVBAgMBkxpc2JvbjEPMA0GA1UEBwwGTGlzYm9uMRAwDgYDVQQKDAdQcm9iZWx5MRQwEgYDVQQDDAtwcm9iZWx5LmNvbTAeFw0yMTAxMTExNTEyMDBaFw0zMTAxMTExNTEyMDBaMFcxCzAJBgNVBAYTAlBUMQ8wDQYDVQQIDAZMaXNib24xDzANBgNVBAcMBkxpc2JvbjEQMA4GA1UECgwHUHJvYmVseTEUMBIGA1UEAwwLcHJvYmVseS5jb20wggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQDBIuwIGTIDaKPvv8lRKNlQVRD/lZgUeeSifEGl81JywWIDKWqvrXv07dupDoEAodwX9mfl68RfrBi4SfB1FYijEl7axURJgUrijCYolF76zxhcSVwadlzR9uOQZu/y//mwEZZtuYk62s1XM6o94pomR9Iv+ODoD9QgIARJEXTo/c0a55pt1Ps5yepUAHrr2JQaKyzgqrYeh3wXjKUf74MIWo3HNeRK16q5GSEdWs5bzjhdEynm8PCsAJ8kLqn/JawLgbhnOKVtgHf/DvywgVR+r3ZdFlqzKQOIiTD0y0n+Niy8jVI50xPT0Sf4H+jzW1VUhKuU2hbuPjUbPAoIiCDm0KquUfGJNkmPO8wfFwSN9HJLGBS8J56IvDf6yib5u111ddVqY6nfq/lMydrRlahV1ifouiep9vNsG9pbDy63biXVyyZD+0M8vom3AoeV5Vi6WM6OitrmzjevPy2XdPzCmmPFsUiQaAMNvgrYlE5OmeAyRQiBAlBlzDWBdRQBHmzVfcwB4TIdFcwBA2hkCDOkX/StrPb66YHMd4l6BIfGNgpGXyUDeDw8sV0R9Z8UXAHZ7C/CkgCwiLXGXpKMYcXLW8+51TC+SFksBGq6xSv4rBTTIP/+BewWyrG4F9E08VY0wEwa7fS19Ub/sC5s0TZxc9udLODlPhXKqvUC2qfGBQIDAQABo1MwUTAdBgNVHQ4EFgQUZAuqKmA9OaaqrLYoDtKVPtCXA3MwHwYDVR0jBBgwFoAUZAuqKmA9OaaqrLYoDtKVPtCXA3MwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAgEAZsze5LAdBkRBLmEK57E1Wp+3rhLIPjF49/riQcQZPhGV2ED4elMWsGbBTzPAeInq1m8FqMPCuAAU9Sbv+WmjzcJeDY2Re0jelmkSpiGejpRMdYhmoH3WOvHo1SfqZrlTowKKJ9qVp/nqMRMMxxjwvKvcjRjzdANl1oxitT6MjF7ISIQSHMi/sAXvYKprgcCdr+10bY+hQuK/r952Kd+YetTbfvS3B5UvhtJwCl1g3SUZCQ8n0Erxsg5rME2d10Ykva6UNlTeEEBsVWkvgkZTYzVv06T+BBIo8XX/FuwTnFj2Goej+CGxCntuFR+JMwuSX3eZKSVts3S7/ytGDFE3DKREN/xexARTICbl4+lCpvrdYIZHUR4YXTCAuw9OpYilWF/A/KlJb2aZWHI/RCDG2I7mwvA+Q9q+W5WNhBhYgeqvmF5bj0hDdVG0CpoGQEe34xasd0+EgoNlxJ565+fgXYdPdOCwXau1epRSYNNdWgjQFVs5oGhA0dbtfYQTjMN7WthvaXJNFofN4BvrGsEufIJwHTYbeHizbGu6dUxLCCLtVYVOHoF+EmL17djSU5PIT3bshDg2qmC/uJS/HTdr5NRybCyy3F8c5P7oDeVTbcqBRMY2e0ZxjJMMrwehU2q+gZovNRVTybplQXuvGzg3r0yuhRjQ1dWhKAZkEcV7B/Y=
```

## Step 2: Configure SSO in Snyk API & Web

With Snyk API & Web configured in your Identity Provider, the second part of the SSO configuration is on the Snyk API & Web side. For that, you must provide the following information:

* Your Entity Identifier.
* Your Certificate.
* The URL of your SSO or the URL with the metadata.
* The SAML claims with information about:
  * The first name.
  * The last name.
  * The email.

You can also map your SAML Groups to [Snyk API & Web Roles](/scan-fix-and-prevent/scan-with-snyk/snyk-api-web/managing-account/roles-and-permissions.md) and specific scopes (global to the account, a [team](/scan-fix-and-prevent/scan-with-snyk/snyk-api-web/managing-account/get-started-with-teams.md), or a target). In this case, you must provide Snyk API & Web with the SAML claim with the information about the SAML Groups and tell Snyk API & Web how the mapping is done. Here is an example:

| SAML Group         | Snyk API & Web Role | Snyk API & Web Scope |
| ------------------ | ------------------- | -------------------- |
| probely\_admin     | Admin               | Global (account)     |
| teamX\_admin       | Admin               | Team X               |
| teamX\_developers  | Developer           | Team X               |
| portal\_developers | Developer           | Portal Target        |

This mapping produces the following results:

* Users belonging to **probely\_admin** receive **Admin** permissions to the whole Snyk API & Web account (global scope). They can view and take action on any target of your account.
* Users belonging to the groups **teamX\_admin** and **teamX\_developers** only perform actions on targets of **Team X**, with permissions to do what the respective **Admin** and **Developer** roles allow.
* Users belonging to **portal\_developers** receive the permissions given by the **Developer** role and only perform actions on a single target: the **Portal Target**.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.snyk.io/scan-fix-and-prevent/scan-with-snyk/snyk-api-web/managing-account/set-up-single-sign-on-sso-in-snyk-api-web.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
