Single sign-on and SCIM
Let staff sign in to Agoo with Google, Microsoft or your SAML identity provider, and create and deactivate their accounts automatically with SCIM.
This is designed and scheduled but not built yet. We document it now so you can plan your integration.
Single sign-on (SSO) lets your staff sign in to the Agoo console and Workspace app with the account they already use at work, under your organisation's password and two-step verification rules. SCIM provisioning keeps Agoo's list of people in step with your identity provider: joiners appear, leavers are deactivated, without anyone editing Agoo by hand.
What's included on each plan
| Plan | Sign-in | Provisioning |
|---|---|---|
| Free, Starter | Email and password, with two-step verification for admins | CSV import |
| Growth | Plus Sign in with Google and Sign in with Microsoft | CSV import |
| Pro | Plus SAML 2.0 with any SAML identity provider, and SSO enforcement | Plus SCIM 2.0 |
| Enterprise | Plus custom identity provider setups, such as OpenID Connect providers or several identity providers, set up with our team | Plus HR system sync, see HR and payroll |
Sign in with Google and Microsoft arrives with the Tenant Console in phase P3. SAML and SCIM arrive in phase P9.
Sign in with Google or Microsoft
On Growth and above, people whose Agoo account email matches their Google Workspace or Microsoft 365 account can choose Continue with Google or Continue with Microsoft on the sign-in page. There's nothing to configure in Agoo. If your organisation restricts third-party apps, your IT team may need to allow Agoo once in the Google Admin console or the Microsoft Entra admin center.
This is sign-in only. It doesn't create accounts: people still need to be added to Agoo, by an admin, by CSV import or by SCIM.
SAML single sign-on
Before you start
- You're an Agoo Owner or Admin on the Pro or Enterprise plan.
- You're an administrator of your identity provider.
- You know the email domains your staff use, such as
voltabank.example.
In Agoo: start the setup
Open Settings → Security → Single sign-on
Choose Set up SAML.
Add and verify your email domains
Add each email domain that should sign in through your identity provider. Agoo gives you a DNS TXT record for each one; add it at your DNS provider and select Verify. This proves the domain is yours, so no other organisation can claim your staff's sign-ins.
Copy Agoo's service provider details
Agoo shows the values your identity provider needs: the Entity ID (also called Identifier or Audience URI), the ACS URL (Reply URL), and a metadata URL that contains both. Keep this page open.
In your identity provider
- In the Microsoft Entra admin center, go to Enterprise applications → New application → Create your own application.
- Name it
Agoo, choose Integrate any other application you don't find in the gallery (Non-gallery) and select Create. - Open Single sign-on and choose SAML.
- In Basic SAML Configuration, paste Agoo's Entity ID into Identifier (Entity ID) and the ACS URL into Reply URL (Assertion Consumer Service URL). Save.
- In Attributes & Claims, check that the Unique User Identifier (Name ID) is
user.mail(oruser.userprincipalnameif that is the same as people's email address), and thatgivenname,surnameandemailaddressclaims are present. They are by default. - In SAML Certificates, copy the App Federation Metadata Url.
- In Users and groups, assign the people or groups who should use Agoo.
Back in Agoo: finish and test
Add your identity provider's metadata
Paste the metadata URL, or upload the metadata XML. With a URL, Agoo picks up certificate changes on its own.
Test with your own account
Select Test sign-in. Agoo opens your identity provider in a new window and shows exactly what it received. Fix any missing attribute before going further.
Turn it on, then enforce it
Turn SSO on. People with your verified domains are now sent to your identity provider when they sign in.
When you're confident it works, turn on Require SSO so password sign-in stops working for those domains. Keep at least one Owner who can sign in without SSO (with a password and two-step verification) in case your identity provider has an outage.
Kiosks are not affected: they are paired devices, not people, and keep working through any SSO change.
SCIM provisioning
SCIM lets your identity provider create, update and deactivate people in Agoo. It's available on Pro and Enterprise.
| SCIM setting | Value |
|---|---|
| Base URL | https://api.agoo.ardent.africa/scim/v2 |
| Authentication | Bearer token, created in Settings → Security → SCIM (shown once) |
| Resources | Users and Groups |
| Protocol | SCIM 2.0 (RFC 7643, RFC 7644) |
What SCIM changes in Agoo:
| In your identity provider | In Agoo |
|---|---|
| A user is assigned to the Agoo app | A person is created, with their name, email and (if sent) phone number and job title |
| A user's details change | The person is updated |
| A user is unassigned or set inactive | The person is deactivated: they can't sign in, and they leave host search and attendance |
| A group is pushed | A department with the group's name, with its members |
Roles (such as Receptionist or Admin) and sites are assigned in Agoo, not by SCIM, so a change in your directory can never make someone an admin by accident. Deactivated people are never deleted by SCIM: their visit and attendance history stays, under your retention settings.
The SCIM token is separate from API keys. It can only manage people and departments, and it's shown in the audit trail as "SCIM".
Microsoft Entra ID
- In the
Agooenterprise application, open Provisioning and set Provisioning Mode to Automatic. - Under Admin Credentials, enter
https://api.agoo.ardent.africa/scim/v2as the Tenant URL and your SCIM token as the Secret Token. Select Test Connection, then save. - Under Mappings, keep the default user attributes. Map
mailtouserNameif your user principal names differ from email addresses. - Set Provisioning Status to On and save.
Entra ID provisions in cycles, so changes can take up to about 40 minutes to reach Agoo. Use Provision on demand to push one person straight away.
Google Workspace
Google Workspace only offers automatic provisioning to apps in its own catalogue, not to custom SAML apps. Use Agoo's Google directory sync instead, in Settings → Security → Directory sync: it reads users and groups from your Google Workspace directory with read-only access and applies the same rules as SCIM.
Other providers
Any SCIM 2.0 client can use the base URL and token above, including Okta and JumpCloud. Users are matched on userName, which must be the person's work email address.
Troubleshooting
Check that they're assigned to the Agoo app in your identity provider, and that their Name ID is the same email address as their Agoo account.
Your provider's signing certificate may have changed. If you uploaded metadata XML, upload the new metadata, or switch to a metadata URL so changes are picked up automatically.
Check the base URL ends in /scim/v2 with no trailing slash, and that the token hasn't been regenerated since you copied it. SCIM needs the Pro
or Enterprise plan.
Sign in as the Owner you kept outside SSO and turn off Require SSO until the provider is back. Kiosks keep checking people in throughout.
Related
Google and Microsoft calendars
Connect Google Workspace or Microsoft 365 calendars so booking pages respect hosts' real availability, bookings land in their calendars, and meeting invites carry Meet or Teams links.
Slack and Microsoft Teams
Send arrival alerts and approval requests to hosts in Slack or Microsoft Teams, and post arrivals to a channel.