SSO is not enabled by default. To enable SSO for your account, contact your Pickcel sales representative or email contact@pickcel.com.
Before you begin
Prerequisites
Prerequisites
- Your Pickcel account has been created and onboarding is complete
- SSO has been enabled for your account by the Pickcel team
- You have your identity provider details ready
- You have chosen a Tenant ID for your organization
Supported authentication methods
Supported authentication methods
Pickcel supports three authentication methods:
Choose the method recommended by your IT team and supported by your identity provider.
| Method | Description |
|---|---|
| SAML | Security Assertion Markup Language - XML-based standard |
| OIDC | OpenID Connect - OAuth 2.0-based identity layer |
| JWT | JSON Web Token - Compact token format |
Tenant ID requirements
Tenant ID requirements
Your Tenant ID:
- Must be unique across all Pickcel accounts
- Cannot contain spaces
- Should not exceed 40 characters
Request SSO enablement
SSO must first be enabled by Pickcel before you can configure it.Contact Pickcel
Reach out to your Pickcel sales representative or email contact@pickcel.com to request SSO enablement.
Configure SSO in Pickcel
Open SSO settings
Sign in to Pickcel, click your profile icon in the top-right corner, select Settings, then click Set Up SSO.
Enter your SSO details
Fill in the required fields:
Click Proceed when ready.
| Field | Description |
|---|---|
| Tenant ID | A unique identifier your users will enter when signing in with SSO |
| Provider Name | A friendly name for your identity provider (e.g., Okta, Cognito) |
| Auth Type | Select SAML, OIDC, or JWT |
Identity provider configuration
- SAML
- OIDC
- JWT
When configuring SAML, you will need to:
- Copy Pickcel’s redirect URL to your identity provider
- Configure audience or entity ID settings
- Upload or exchange metadata/XML between Pickcel and your IdP
Sign in with SSO
Once SSO is configured, users can sign in using their organizational credentials.Go to Pickcel sign-in page
Open console.pickcel.com in your browser.
Authenticate with your IdP
You’ll be redirected to your organization’s identity provider. Sign in with your work credentials.
After first SSO login
After a user signs in with SSO for the first time, your Pickcel admin may need to:
- Assign appropriate roles
- Configure permissions
- Allocate resources
Important information
Key points to remember
Key points to remember
- SSO is not enabled by default and must be requested through Pickcel
- Your account must be created and onboarding completed before SSO setup
- You must log out and log back in after Pickcel enables SSO to see the setup option
- Only one SSO integration can be active per account
- Only one auth type can be enabled at a time
Tenant ID rules
Tenant ID rules
- Must be unique
- Cannot contain spaces
- Should not exceed 40 characters
FAQ
Do I need to contact Pickcel before setting up SSO?
Do I need to contact Pickcel before setting up SSO?
Yes. SSO must first be enabled for your account by the Pickcel team before you can configure it.
Where do I find the SSO setup option?
Where do I find the SSO setup option?
Navigate to: Profile icon → Settings → Set Up SSO
Which auth type should I choose?
Which auth type should I choose?
Choose the auth type used by your organization’s identity provider and recommended by your IT team. Available options are:
- SAML - Most common for enterprise SSO
- OIDC - Modern OAuth 2.0-based approach
- JWT - Token-based authentication
Can I enable both SAML and OIDC for the same account?
Can I enable both SAML and OIDC for the same account?
No. Only one SSO method can be enabled at a time per Pickcel account.
Why can't I see Change Password or MFA in Pickcel?
Why can't I see Change Password or MFA in Pickcel?
When SSO is enabled, authentication is handled entirely by your identity provider. Because of this, password management and MFA options are hidden in Pickcel—these are now managed through your IdP.
Can Pickcel admins still manage users after SSO is enabled?
Can Pickcel admins still manage users after SSO is enabled?
Yes. Pickcel admins can still assign roles, permissions, and resources to users after they sign in through SSO.