Identity

Claro + SAML SSO

Let employees sign in with the identity provider they already use, instead of managing another password.

Overview

Claro supports SAML 2.0 single sign-on so your organization's identity provider, such as Azure AD/Entra or Okta, becomes the single place employees authenticate. Each tenant configures its own identity provider settings independently, so a managed service provider or holding company running multiple Claro tenants can connect a different IdP per tenant without conflict. New users can be provisioned automatically on their first login through just-in-time provisioning, so there is no manual account-creation step before someone can access their training.

For organizations that want to fully retire local passwords, Claro offers an SSO-only enforcement option that requires authentication through the identity provider. This is useful when a tenant wants to guarantee that access to Claro follows the same identity governance as every other corporate application, including conditional access, multi-factor requirements, and centralized session control.

SSO reduces both friction and risk. Employees skip yet another password, which removes a common reason training goes uncompleted, and your security team removes a standalone credential that could be phished or reused. Because authentication happens at your identity provider, any control you already enforce there, such as blocking risky sign-ins or requiring MFA, automatically extends to Claro without separate configuration.

The integration is built on the SAML 2.0 standard rather than a single vendor, so any compliant identity provider works. Configuration is handled per tenant through metadata, an entry point, and a signing certificate, with attribute mapping that tells Claro how fields like email and name arrive from your IdP. For regulated environments, this centralized, standards-based approach makes access to Claro auditable alongside the rest of your identity estate.

How it works

  • Configure your identity provider

    Add your IdP's metadata (entry point, certificate, or metadata URL) to Claro's per-tenant SSO settings so Claro can trust assertions from your provider.

  • Map user attributes

    Define how identity provider attributes such as email and name map to Claro user fields, so provisioned accounts carry the right identity details.

  • Test the connection

    Verify the SSO configuration with a test sign-in before rollout, confirming assertions validate and users land in Claro as expected.

  • Users sign in through the IdP

    Employees authenticate with the identity provider and are signed into Claro, with new users provisioned automatically on first login if enabled.

  • Enforce SSO-only if required

    Optionally require all sign-ins to go through the identity provider, retiring local passwords so Claro access follows the same governance as your other apps.

Frequently asked questions

  • Claro supports any SAML 2.0 compliant identity provider, including common ones like Azure AD/Entra and Okta, since the integration is built on the SAML 2.0 standard rather than a specific vendor.

Not sure how Claro fits your stack?

Tell us what you run today and we will walk you through the integration path.

Request a demo