Open navigation

Single Sign-On

Canto supports the use of single sign-on with SAML 2.0.


If you are interested in learning more about our SSO service, please contact your Canto Account Manager.


If you have purchased SSO and are ready to begin with the setup, please create a support ticket in our Help Center and provide us with the following details:


  1. What identity provider (IdP) are you using, e. g. ADFS, Azure or G-Suite?
  2. Who should be able to log in to Canto? IdP users only or your IdP users + users that have been manually created in Canto and are not part of your IdP environment (e. g. agencies, partners or customers)?
  3. Do you want to manage Canto roles for your IdP users within your IdP or in Canto?
  4. Do you want to manage Canto groups for your IdP users within your IdP or in Canto?
  5. Do you want to allow Canto consumers to access your Main Library or not?


By default, every new user created in Canto - that originates from your SSO environment - will be a Consumer user.

Depending on the setup (see step 3 and 4 of the questions above) you need to adjust their roles as desired, either in Canto or in your SSO environment.


Below you can find setup guides for our most commonly connected IdPs:



If your system is not listed above but SAML 2.0 compatible, our technical team will be able to help you with the configuration.

During the configuration, we will provide our service provider with metadata details (XML file) to be used for the configuration within your IdP.


We have three required login attributes which need to be sent over from your IdP for authorization:

  • first name
  • last name
  • email address


Please refer to this article for the frequently asked questions regarding Single Sign On.

You may also want to check out our article about how to setup multiple IdPs.


Did you find it helpful? Yes No

Send feedback
Sorry we couldn't be helpful. Help us improve this article with your feedback.