SSO

Single sign-on, per organization

Formward's SSO is OIDC, configured once per organization. Each org connects its own identity provider; anyone who signs in through it is provisioned straight into that org's membership, no separate Formward invite required. It is available on the Business plan.

How it works

SSO is scoped to the organization, not the individual user. An org owner or admin registers the identity provider once; every future sign-in through it lands the user in that organization with membership already in place. There is one provider per organization.

Set it up

  1. 1. Register an application for Formward with your identity provider, and note its OIDC issuer URL, client ID, and client secret.
  2. 2. Open SSO settings in the Formward dashboard (org owner or admin only) and enter the issuer, your organization's email domain, client ID, and client secret.
  3. 3. Allowlist the callback URL the settings page shows once saved, in your identity provider's redirect configuration.
  4. 4. Sign in through the provider. The first successful sign-in provisions the user into the organization automatically.

Supported today, and what is not

  • Supported: OIDC, one identity provider per organization, automatic provisioning into org membership on first sign-in.
  • Supported: SCIM 2.0 user provisioning and deprovisioning, driven by a token you issue in the dashboard. Works with Okta, Entra ID and any SCIM 2.0 client.
  • Not self-serve: SAML. OIDC is what you can configure yourself; if your identity provider only speaks SAML, talk to us first.

For the fuller enterprise picture β€” data residency, audit log, team roles, and what else we do and don't have β€” see the enterprise page.

Frequently asked questions

How does SSO work on Formward?
SSO is per-organization OIDC. An org owner or admin registers their identity provider once, from the dashboard's SSO settings, by entering its issuer URL, client ID, and client secret. From then on, anyone signing in through that provider is provisioned directly into that organization's membership.
Which plan do I need?
SSO is gated to the Business plan. Entitlement is checked against the plan of the organization's billing owner, so it applies to the whole organization, not per member.
Do you support SAML?
Not as a self-serve option. What you can configure yourself in the dashboard is OIDC. If your identity provider only exposes SAML, contact sales@formward.eu and we will work out whether we can support you.
Do you support SCIM for automatic user provisioning?
Yes. SCIM 2.0 provisioning and deprovisioning are available on the Business plan. You issue a SCIM token from the SSO settings page and point your identity provider at it; users created, updated or deactivated there are synced into the organization's membership. SSO alone also provisions a user on their first sign-in, so SCIM is what you add when you want membership pushed from the IdP rather than pulled at login.
What do I need from my identity provider to set this up?
Your provider's OIDC issuer URL, a client ID and client secret from an application registered for Formward, and your provider's redirect/callback field pointed at the callback URL the SSO settings page shows once you save your issuer and domain.

Bring your team's identity provider

SSO is included on Business, 20,000 submissions a month, 50 seats.

Single sign-on (SSO) for your form backend | Formward