Single sign-on & SCIM
What this is for If your lab already runs an identity provider — Okta, Microsoft Entra, OneLogin, Ping, JumpCloud or ADFS — your team can sign in to Casetop with it. You can also have accounts created automatically as you add people in your directory, and deactivated when you offboard them. None of this is needed for a smaller lab. Signing in with Google or Microsoft, or with a password, keeps working exactly as it does now; this is only for a lab whose IT department runs its own provider. Everything lives at Lab → Settings → Sign-in, and only an owner can change it — these settings decide who can get into your lab at all. 1. Prove your email domain Add your domain (for example yourlab.com) and we show you a TXT record to add to your DNS. Until it verifies, nobody is routed to your provider. If you have already verified that exact domain for lab-branded email, it counts — you have proved the same thing once already. A public domain like gmail.com cannot be claimed, and a domain can belong to one lab only. 2. Point at your provider For OpenID Connect (Okta, Entra, OneLogin, Ping and most others) you need the discovery URL, a client ID and a client secret. For SAML 2.0 you need the sign-in URL, the entity ID and the signing certificate. The screen shows you the redirect, ACS and metadata URLs to give to whoever configures the provider — typed from memory, those are the commonest thing to get wrong. Keep the next certificate alongside the current one during a rotation. Two are accepted at once, which is what turns a key change into a non-event instead of an outage. Test configuration checks your settings and names what is missing before anyone tries to sign in. How your team signs in They type their email on the normal sign-in page and a Continue with … button appears, labelled however you named it. If you have turned passwords off for your domain, the password box is not offered at all. 3. People and passwords Create accounts automatically means anyone at a verified domain who signs in through your provider gets an account, with the role you nominate. It is off by default — otherwise you invite each person, which is how Casetop works without this. Owner is never granted by a provider. Ownership is a billing relationship with us, not a group in your directory. Turn passwords off for your domain requires your team to come in through your provider. You, as owner, keep a password — deliberately. If your provider is ever misconfigured, that is the way back in, and we cannot fix your Okta for you. This covers every other way in, not just passwords: signing in with Casetop’s own Google or Microsoft buttons is refused too, because those are our apps rather than yours. Floor accounts are unaffected either way: they sign in with a PIN and have no email address. 4. Joiners and leavers (SCIM) Create a SCIM token and give it, with the base URL shown, to your provider’s connector. People you add in your directory get accounts here; people you offboard are deactivated here. Without it, someone who leaves keeps their access until a person remembers to remove them. The token is shown once. Deactivating does not delete anybody — their name is on case history, the piece-work ledger and the audit trail, and that record is never thrown away.
This page uses JavaScript to render its full interactive content. Enable JavaScript, or continue reading at
https://casetop.io/docs/single-sign-on.