Learn how to enable and configure Single Sign-On (SSO) for your Pickcel account.
Single Sign-On (SSO) lets your users sign in to Pickcel using your organization’s identity provider, such as Okta or Amazon Cognito. This helps simplify access and centralize authentication for your team.
SSO is not enabled by default. To enable SSO for your account, contact your Pickcel sales representative or email contact@pickcel.com.
Do I need to contact Pickcel before setting up SSO?
Yes. SSO must first be enabled for your account by the Pickcel team before you can configure it.
Where do I find the SSO setup option?
Navigate to: Profile icon → Settings → Set Up SSO
Which auth type should I choose?
Choose the auth type used by your organization’s identity provider and recommended by your IT team. Available options are:
SAML - Most common for enterprise SSO
OIDC - Modern OAuth 2.0-based approach
JWT - Token-based authentication
Can I enable both SAML and OIDC for the same account?
No. Only one SSO method can be enabled at a time per Pickcel account.
Why can't I see Change Password or MFA in Pickcel?
When SSO is enabled, authentication is handled entirely by your identity provider. Because of this, password management and MFA options are hidden in Pickcel, these are now managed through your IdP.
Can Pickcel admins still manage users after SSO is enabled?
Yes. Pickcel admins can still assign roles, permissions, and resources to users after they sign in through SSO.