How it works
SAML is a standard that lets your identity provider vouch for a user to an app. Two sides take part:- Your identity provider (Okta) knows who your people are and checks their password and MFA.
- Peeps trusts your identity provider’s word for who is signing in.
1
Start at Peeps
Someone opens the Peeps login page, chooses Sign in with SSO, and enters their work email.
2
Sign in at Okta
Peeps sends them to your Okta, where they sign in, or pass straight through if they already have.
3
Back to Peeps
Okta sends them back to Peeps with a signed statement of who they are. Peeps checks the signature and signs them in.
Who gets in
Anyone you assign to the Peeps app in Okta can sign in, as long as their email is on one of your organization’s verified domains. Assigning the app is how you give someone Peeps; there’s no separate invite.- New people join your Peeps organization as a contributor. You can change their role afterwards under Settings → Organization → Members.
- People who already use Peeps with the same email keep their account and everything in it. SSO simply becomes another way to sign in to it.
- People on other email domains, such as contractors, can’t use SSO. Invite them to Peeps as usual.
Removing access
Getting started
SSO is set up for your organization together with Peeps. Email support@peepsai.com with your organization’s name and the email domains your people use, then follow Set up Okta.Limitations
- Sign-in has to start from the Peeps login page. The Peeps tile on the Okta dashboard doesn’t sign you in.
- Roles are managed in Peeps. Okta groups don’t map to Peeps roles.
- You can’t yet require SSO for everyone in your organization.