Docs
Integrations

Single sign-on and SCIM

Let staff sign in to Agoo with Google, Microsoft or your SAML identity provider, and create and deactivate their accounts automatically with SCIM.

Planned· P9For IT admins

This is designed and scheduled but not built yet. We document it now so you can plan your integration.

Single sign-on (SSO) lets your staff sign in to the Agoo console and Workspace app with the account they already use at work, under your organisation's password and two-step verification rules. SCIM provisioning keeps Agoo's list of people in step with your identity provider: joiners appear, leavers are deactivated, without anyone editing Agoo by hand.

What's included on each plan

PlanSign-inProvisioning
Free, StarterEmail and password, with two-step verification for adminsCSV import
GrowthPlus Sign in with Google and Sign in with MicrosoftCSV import
ProPlus SAML 2.0 with any SAML identity provider, and SSO enforcementPlus SCIM 2.0
EnterprisePlus custom identity provider setups, such as OpenID Connect providers or several identity providers, set up with our teamPlus HR system sync, see HR and payroll

Sign in with Google and Microsoft arrives with the Tenant Console in phase P3. SAML and SCIM arrive in phase P9.

Sign in with Google or Microsoft

On Growth and above, people whose Agoo account email matches their Google Workspace or Microsoft 365 account can choose Continue with Google or Continue with Microsoft on the sign-in page. There's nothing to configure in Agoo. If your organisation restricts third-party apps, your IT team may need to allow Agoo once in the Google Admin console or the Microsoft Entra admin center.

This is sign-in only. It doesn't create accounts: people still need to be added to Agoo, by an admin, by CSV import or by SCIM.

SAML single sign-on

Before you start

  • You're an Agoo Owner or Admin on the Pro or Enterprise plan.
  • You're an administrator of your identity provider.
  • You know the email domains your staff use, such as voltabank.example.

In Agoo: start the setup

Open Settings → Security → Single sign-on

Choose Set up SAML.

Add and verify your email domains

Add each email domain that should sign in through your identity provider. Agoo gives you a DNS TXT record for each one; add it at your DNS provider and select Verify. This proves the domain is yours, so no other organisation can claim your staff's sign-ins.

Copy Agoo's service provider details

Agoo shows the values your identity provider needs: the Entity ID (also called Identifier or Audience URI), the ACS URL (Reply URL), and a metadata URL that contains both. Keep this page open.

In your identity provider

  1. In the Microsoft Entra admin center, go to Enterprise applications → New application → Create your own application.
  2. Name it Agoo, choose Integrate any other application you don't find in the gallery (Non-gallery) and select Create.
  3. Open Single sign-on and choose SAML.
  4. In Basic SAML Configuration, paste Agoo's Entity ID into Identifier (Entity ID) and the ACS URL into Reply URL (Assertion Consumer Service URL). Save.
  5. In Attributes & Claims, check that the Unique User Identifier (Name ID) is user.mail (or user.userprincipalname if that is the same as people's email address), and that givenname, surname and emailaddress claims are present. They are by default.
  6. In SAML Certificates, copy the App Federation Metadata Url.
  7. In Users and groups, assign the people or groups who should use Agoo.

Back in Agoo: finish and test

Add your identity provider's metadata

Paste the metadata URL, or upload the metadata XML. With a URL, Agoo picks up certificate changes on its own.

Test with your own account

Select Test sign-in. Agoo opens your identity provider in a new window and shows exactly what it received. Fix any missing attribute before going further.

Turn it on, then enforce it

Turn SSO on. People with your verified domains are now sent to your identity provider when they sign in.

When you're confident it works, turn on Require SSO so password sign-in stops working for those domains. Keep at least one Owner who can sign in without SSO (with a password and two-step verification) in case your identity provider has an outage.

Kiosks are not affected: they are paired devices, not people, and keep working through any SSO change.

SCIM provisioning

SCIM lets your identity provider create, update and deactivate people in Agoo. It's available on Pro and Enterprise.

SCIM settingValue
Base URLhttps://api.agoo.ardent.africa/scim/v2
AuthenticationBearer token, created in Settings → Security → SCIM (shown once)
ResourcesUsers and Groups
ProtocolSCIM 2.0 (RFC 7643, RFC 7644)

What SCIM changes in Agoo:

In your identity providerIn Agoo
A user is assigned to the Agoo appA person is created, with their name, email and (if sent) phone number and job title
A user's details changeThe person is updated
A user is unassigned or set inactiveThe person is deactivated: they can't sign in, and they leave host search and attendance
A group is pushedA department with the group's name, with its members

Roles (such as Receptionist or Admin) and sites are assigned in Agoo, not by SCIM, so a change in your directory can never make someone an admin by accident. Deactivated people are never deleted by SCIM: their visit and attendance history stays, under your retention settings.

The SCIM token is separate from API keys. It can only manage people and departments, and it's shown in the audit trail as "SCIM".

Microsoft Entra ID

  1. In the Agoo enterprise application, open Provisioning and set Provisioning Mode to Automatic.
  2. Under Admin Credentials, enter https://api.agoo.ardent.africa/scim/v2 as the Tenant URL and your SCIM token as the Secret Token. Select Test Connection, then save.
  3. Under Mappings, keep the default user attributes. Map mail to userName if your user principal names differ from email addresses.
  4. Set Provisioning Status to On and save.

Entra ID provisions in cycles, so changes can take up to about 40 minutes to reach Agoo. Use Provision on demand to push one person straight away.

Google Workspace

Google Workspace only offers automatic provisioning to apps in its own catalogue, not to custom SAML apps. Use Agoo's Google directory sync instead, in Settings → Security → Directory sync: it reads users and groups from your Google Workspace directory with read-only access and applies the same rules as SCIM.

Other providers

Any SCIM 2.0 client can use the base URL and token above, including Okta and JumpCloud. Users are matched on userName, which must be the person's work email address.

Troubleshooting

On this page