Configuring Integration with Identity Providers

This functionality is available on Onshape's browser, iOS, and Android platforms.

Before starting the integration process, you must have requested, and been approved for, an Onshape Enterprise account or trial, and have an Onshape Enterprise domain name.

An example of an Enterprise domain name might be:

Note that you are only able to use one Single Sign On (SSO) provider at a time.

Onshape supports the following identity providers for single sign-on (SSO) purposes:

  • Okta
  • Microsoft Azure AD
  • Microsoft ADFS
  • Google
  • Ping Identity

The set up for each of these identity providers varies and is explained in separate topics, but the overall steps are similar to these:

  1. Add Onshape to your single sign on account.
  2. Download the required configuration file from your single sign on account.
  3. Upload the configuration file into Onshape.
  4. In your Onshape administrator account, enable the single sign on provider for your users.
  5. Do a hard refresh of your Onshape sign in page, then sign in with your SSO credentials.
  6. If desired, at this point you can disable the ability for your users to sign in to Onshape except through the SSO provider.


Was this article helpful?

Last Updated: June 25, 2020