Single sign-on

Single sign-on (SSO) lets your team log in to Riddle through your company's identity provider (IdP) instead of a Riddle password. Riddle supports SAML 2.0 and OAuth 2.0 / OpenID Connect (OIDC), so SSO works with any standards-compliant identity provider, including:

  • Microsoft Entra ID (Azure AD)
  • Okta
  • OneLogin
  • Auth0
  • Google Workspace
  • Keycloak

Good to know: SSO is part of the Enterprise plan. Our team sets it up for your organization – there is nothing to configure in the Riddle Creator yourself.

How login with SSO works

Login always starts at Riddle (SP-initiated):

  1. The user clicks on LOG IN on Riddle.com and enters their email address.
  2. Riddle redirects them to your identity provider.
  3. They sign in there, with multi-factor authentication if your identity provider requires it.
  4. Your identity provider sends them back to Riddle, which identifies them by their email address and logs them in.

See Log in to Riddle for the login steps from a user's point of view.

Supported protocols

SAML 2.0OAuth 2.0 / OpenID Connect
Login flowSP-initiated – Riddle redirects users to your identity providerSP-initiated – Riddle redirects users to your identity provider
How Riddle verifies the loginAssertions must be signed. Riddle checks the signature against your X.509 certificate and validates the issuer.Authorization Code flow with your client ID and client secret
BindingHTTP-POST–
User identificationEmail address, from the email attribute of the assertionEmail address

What changes for your users

  • Every user needs a seat first. Riddle does not create accounts on the first SSO login. Each user must already have a seat on your organization's Riddle account, with the same email address as in your identity provider. Just-in-time provisioning and SCIM are not supported.
  • No more password login. Once SSO is enabled for your organization, password login is disabled for its users. Every login goes through your identity provider.
  • MFA is handled by your identity provider. Your existing multi-factor authentication policies apply to Riddle automatically.

Set up SSO

  1. Contact us via the support chat or via email and let us know which protocol you want to use. We send you your organization ID.
  2. Register Riddle as an application in your identity provider, using the values below.
  3. Send us the details of your identity provider (see below).
  4. Our team configures SSO for your organization and lets you know when it is active. From then on, your users log in via SSO.

Values for your identity provider

SettingValue
ACS URL (SAML) / Redirect URI (OIDC)https://www.riddle.com/creator/auth/sso/callback/<your-organization-id>
SP Entity ID (SAML, if your identity provider asks for one)https://www.riddle.com/creator/auth/sso/metadata
SAML bindingHTTP-POST
Required SAML attributeemail – the user's email address

Replace <your-organization-id> with the organization ID you received from us.

Details we need from you

SAML 2.0:

  • The SSO URL (sign-in URL) of your identity provider
  • The entity ID (issuer) of your identity provider
  • The X.509 certificate used to sign the assertions

OAuth 2.0 / OpenID Connect:

  • Client ID and client secret
  • Authorization endpoint
  • Token endpoint
  • Userinfo endpoint

Don't send a discovery URL. For OIDC, Riddle uses the three endpoints directly. A discovery or issuer URL (such as /.well-known/openid-configuration) is not used, so please send the endpoints themselves.

Next steps