Single sign-on
Single sign-on (SSO) lets your team log in to Riddle through your company's identity provider (IdP) instead of a Riddle password. Riddle supports SAML 2.0 and OAuth 2.0 / OpenID Connect (OIDC), so SSO works with any standards-compliant identity provider, including:
- Microsoft Entra ID (Azure AD)
- Okta
- OneLogin
- Auth0
- Google Workspace
- Keycloak
Good to know: SSO is part of the Enterprise plan. Our team sets it up for your organization – there is nothing to configure in the Riddle Creator yourself.
How login with SSO works
Login always starts at Riddle (SP-initiated):
- The user clicks on LOG IN on Riddle.com and enters their email address.
- Riddle redirects them to your identity provider.
- They sign in there, with multi-factor authentication if your identity provider requires it.
- Your identity provider sends them back to Riddle, which identifies them by their email address and logs them in.
See Log in to Riddle for the login steps from a user's point of view.
Supported protocols
| SAML 2.0 | OAuth 2.0 / OpenID Connect | |
|---|---|---|
| Login flow | SP-initiated – Riddle redirects users to your identity provider | SP-initiated – Riddle redirects users to your identity provider |
| How Riddle verifies the login | Assertions must be signed. Riddle checks the signature against your X.509 certificate and validates the issuer. | Authorization Code flow with your client ID and client secret |
| Binding | HTTP-POST | – |
| User identification | Email address, from the email attribute of the assertion | Email address |
What changes for your users
- Every user needs a seat first. Riddle does not create accounts on the first SSO login. Each user must already have a seat on your organization's Riddle account, with the same email address as in your identity provider. Just-in-time provisioning and SCIM are not supported.
- No more password login. Once SSO is enabled for your organization, password login is disabled for its users. Every login goes through your identity provider.
- MFA is handled by your identity provider. Your existing multi-factor authentication policies apply to Riddle automatically.
Set up SSO
- Contact us via the support chat or via email and let us know which protocol you want to use. We send you your organization ID.
- Register Riddle as an application in your identity provider, using the values below.
- Send us the details of your identity provider (see below).
- Our team configures SSO for your organization and lets you know when it is active. From then on, your users log in via SSO.
Values for your identity provider
| Setting | Value |
|---|---|
| ACS URL (SAML) / Redirect URI (OIDC) | https://www.riddle.com/creator/auth/sso/callback/<your-organization-id> |
| SP Entity ID (SAML, if your identity provider asks for one) | https://www.riddle.com/creator/auth/sso/metadata |
| SAML binding | HTTP-POST |
| Required SAML attribute | email – the user's email address |
Replace <your-organization-id> with the organization ID you received from us.
Details we need from you
SAML 2.0:
- The SSO URL (sign-in URL) of your identity provider
- The entity ID (issuer) of your identity provider
- The X.509 certificate used to sign the assertions
OAuth 2.0 / OpenID Connect:
- Client ID and client secret
- Authorization endpoint
- Token endpoint
- Userinfo endpoint
Don't send a discovery URL. For OIDC, Riddle uses the three endpoints directly. A discovery or issuer URL (such as
/.well-known/openid-configuration) is not used, so please send the endpoints themselves.
Next steps
- Log in to Riddle – how your users log in once SSO is active.
- Your user seats – give every colleague a seat before you enable SSO.
- All subscription plans – explained – everything included in the Enterprise plan.

