FixAEO speaks OpenID Connect (OIDC) only. SAML is not supported. If your identity provider can only offer a SAML app for us, that’s a hard no today, not a coming-soon. Any standards-compliant OIDC provider works — Okta, Microsoft Entra ID, OneLogin, and the rest.
Set up single sign-on
Have your provider’s OIDC issuer URL, client ID, and client secret ready before you start. You’ll create the app in your identity provider, then paste its details here.1
Enter your OIDC details
In the Single sign-on card, fill in your Company domain (for example,
company.com), the OIDC issuer URL, Client ID, and Client secret from your provider. Click Save configuration.2
Copy the callback URL into your provider
The card shows a Provider callback URL (
https://api.fixaeo.com/auth/sso/callback). Copy it and paste it into your identity provider’s app as the redirect or callback URL.3
Publish the DNS record and verify
FixAEO shows a TXT record to publish — a Name that looks like
_fixaeo-sso.company.com and a Value. Add it at your DNS provider, then click Verify DNS. This proves you control the domain.4
Test the sign-in
Click Test sign-in and complete a real sign-in through your provider as the admin. This confirms the connection works before anyone relies on it.
5
Enable SSO
Click Enable SSO. People at your verified domain can now sign in to FixAEO through your identity provider.
- One domain binds to one workspace. A company domain can be connected to a single FixAEO organization, not several.
- SSO never creates access on its own. Someone has to already be a member — invited by a teammate or provisioned by directory sync — before they can sign in through your provider. A valid company login is not, by itself, a FixAEO account.
- Turning SSO off keeps your configuration. If you disable it, the saved OIDC details stay, so you can re-enable later without typing them again.
Set up directory sync (SCIM)
Directory sync uses SCIM 2.0. Your identity provider becomes the source of truth for who belongs to the workspace — it adds people when you assign them and removes them when you deprovision them.1
Choose your provider
In the Directory sync card, pick your Identity provider — Okta, Microsoft Entra ID, OneLogin, or Custom SCIM.
2
Create the token
Click Enable and create token. FixAEO shows a SCIM base URL and a bearer token.
3
Copy both into your provider
Paste the base URL and bearer token into your identity provider’s provisioning settings. The token is shown once — copy it now. If you lose it, use Rotate token to issue a new one, which replaces the old.
4
Assign users
Assign the users or groups you want in your identity provider. FixAEO provisions them into the workspace as they’re assigned.
How provisioning behaves
- New members get the Member role and access to all brands. Directory sync controls who’s in and out; roles and per-brand access stay editable inside FixAEO afterward.
- Provisioned members count toward your seat limit, the same as invited teammates. If a sync would push you past your seats, FixAEO refuses that add rather than overfilling — raise your seats or free some up, then it syncs.
- Deactivating a user removes them from this workspace only. Their personal FixAEO account, and any other workspace they belong to, is untouched. Directory removal never deletes an account.
- The workspace owner and the last active admin can’t be removed by directory sync, so an errant deprovision can’t leave the workspace with no one in charge.
Rotating the SCIM token stops your provider from syncing until you paste the new token in, so plan a rotation for a quiet moment. The same is true if you disable directory sync: your provider can no longer add or remove members until you turn it back on.
Related
Team and workspaces
Roles, seats, invites, and how a workspace is organized.
Security and privacy
Sign-in methods, two-factor, and what FixAEO encrypts.
Plans and limits
What Enterprise includes, including seats and engines.
Usage
Seat counts, credits, and per-member activity.