Enterprise customers can provide massive growth for your B2B applications, but they come with their own unique challenges.
Onboarding is one such challenge. With a potentially large user base that might consistently churn, quickly providing new users the access they need can be a huge win for your B2B applications. Combining (or SAML) is an . Admins can also easily map these attributes if they do not match between the two systems, making the system quite flexible.
When Clerk is configured with a SAML connection, users who log in using an email address associated with the connection will automatically be prompted to log in using the specified identity provider. If they log in using a social provider like Google or GitHub, Clerk will detect the email address through those flows as well and ask the user to authenticate with the enterprise connection.
SAML is commonly used in the enterprise space to streamline the onboarding experience for their users while reducing stress on IT and support.
Automated enrollment with verified domains
Clerk .
Configuring SAML
In the Clerk Dashboard sidebar, go to User & authentication >
Next, access your Google Workspace Admin panel and navigate to Apps >
Select Add app, then Add custom SAML app. Google will open a new view to walk you through configuring the app. You’ll be sharing some information between the Clerk Dashboard and Google.
Start by selecting Download Metadata which will download a file containing the configuration for the Google Workspaces App.
Once the upload is finished, take note of the ACS URL and Entity ID values from the Clerk dashboard, you’ll need these for the next step.
Click Continue to move on to step 4. Now you’ll configure attribute mapping which essentially tells Google Workspaces which of its user attributes maps to the attributes in Clerk. Select Add Mapping > Basic Information > Primary Email. In the App attributes field, enter “mail” as the value.
Next, toggle ON for everyone and select Save.
If you are stepping through this guide, you should now be able to authenticate using this SAML connection.
Using verified domains within organizations
To enable automatic enrollment within your application, start by enabling organizations within the Clerk dashboard if you have not already done so. This can be done under Organization Settings. Toggle on the following settings then click Save at the bottom of the screen:
- Unlimited membership
- Enable verified domains
- Automatic invitation
This will open the Organization configuration modal. Verified domains can be added in the General view:
Conclusion
SAML is a common single sign-on strategy used by enterprises all over the world. Your application can be configured to streamline onboarding for your enterprise customers using SAML by enabling verified domains for the organizations belonging to those customers. The result is a simplified experience for your customers, their support teams, and their users!
SOCIAL SHARE CARD GENERATOR