Skip to main content

SSO implementation

PandaDoc supports SSO via IdPs like Okta or OneLogin, using SAML 2.0 for secure, password-free, and fast access across domains.

Availability: Enterprise plan
Business plan: available as a paid add-on ($20/month or $240/year per seat).

Single Sign-On (SSO) allows employees to access PandaDoc securely through an identity provider (IdP) such as Okta, OneLogin, or Microsoft AD FS, eliminating the need for passwords and ensuring fast, secure access.
​

What is SSO?

SSO in PandaDoc is based on Security Assertion Markup Language 2.0 (SAML 2.0), an industry-standard protocol for enabling Single Sign-On across web applications. During the authentication process, no passwords are exchanged with PandaDoc. Instead, PandaDoc receives a temporary, digitally signed SAML assertion that verifies the user's identity.
​

Benefits of SSO for PandaDoc

  • Simplifies secure access to PandaDoc for users.

  • Centralizes user authentication and access control for IT and security teams.

  • Reduces the need for password management, enhancing security and efficiency.

  • Enforces additional security measures like password complexity, expiration, and two-factor authentication (depending on your identity provider’s features).

Enabling SSO

Before enabling SSO it’s important to confirm that:

  1. The email address associated with each user's PandaDoc account matches their email in the company directory.

  2. Confirm compatibility. Confirm that your identity or SSO provider supports federated authentication using SAML 2.0

The list of compatible SSO solutions includes, but is not limited to Okta, OneLogin, and Microsoft AD FS.
​

Configuring SSO for your account

Note: Only the Account Owner can access the Single Sign-On configuration page.

  1. Open Settings, then under Organization, select Single sign-on (SSO).

  2. Choose the Enable Single-sign-on option.
    ​

  3. Specify your company domain and click +Add domain name.
    ​

Verify domain ownership

  1. Log in to the account where you manage your domain (e.g., GoDaddy, Namecheap, Cloudflare).

  2. Navigate to the DNS settings or DNS management area for the domain you want to verify.

Add a new TXT record:

  • Select TXT as the record type.

  • Fill out the fields based on the information provided by your SSO provider:

    • Host/Name: @

    • Value/Content: pandadoc-domain-verification=78HKjufQ9B2e664LAejfKK (this value is an example. Copy your unique value with Copy record on the SSO configuration page).
      ​

    • TTL: You can usually leave this at the default (e.g., 3600 seconds or 1 hour).

Save the changes to add the TXT record to your DNS.

Complete the verification process:

Once the TXT record is added, return to the PandaDoc platform to complete the domain verification process.

Important: The Verify domains button will not appear until you have fully completed the SSO configuration and clicked Save changes at the top of the page. This includes filling out all required SSO settings (such as Identity Provider details, certificate, and general configuration fields).

Please note that it can take anywhere from a few minutes to up to 48 hours for DNS propagation. If the TXT record has not yet propagated, PandaDoc will not be able to verify the domain immediately. If verification fails, wait and try again later.

Fill in the general configuration:

Company domain

If you have multiple domains, add each using the +Add domain button.
​

Password access

By default, the All users may log in using password option is selected. If you want to enable password login for specific users, uncheck the All users may log in using password option and add emails of the users who should be allowed to login via password using the +Add member button. Typically password login is enabled for the account owner.


​

Identity provider

  1. Paste the endpoint in the Provider Link.

  2. Paste the certificate. To replace an existing certificate, click Edit certificate.

Important: Remove the
-----BEGIN CERTIFICATE-----
-----END CERTIFICATE----

lines before pasting.​

Format example:

MIIC8DCCAdigAwIBAgIQHl9uGXsExL9HYFFYN4T21TANBgkqhkiG9w0BAQsFADA0MTIwMAYDVQQD EylNaWNyb3NvZnQgQXp1cmUgRmVkZXJhdGVkIFNTTyBDZXJ0aWZpY2F0ZTAeFw0yMjExMDcxNTI5 MzVaFw0yNTExMDcxNTI5MzRaMDQxMjAwBgNVBAMTKU1pY3Jvc29mdCBBenVyZSBGZWRlcmF0ZWQg U1NPIENlcnRpZmljYXRlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxUhMilHLAg1I u3JoI8JE981KLjdTPUpc9SVd/E0mF9g+wzTvkaeChzqGiOJ5+s90x8bGMLO5RNrbVcfbu8ki460u aEoaymEX5rkXcSl/D17X2PXz30wdiEiwizJWCYRMqAaILxE59w+wjZNQfAaRwaCaP5O4PXAM+5Q+ IcspIQ9aM7v2hV8Mpu7QkDNBTPIIpS27E0Uc8y9phuFHh7U8LMZjqUc+ahUHh+0Lufaiq7d+rY+9 ua16K9P9Dd4/FT/oO55zcnPEc4Pw5sBcul/PYY2apjOPmBZkfmQ8BGaMZ78zMTf71TkZJtsG5nyl p/VYTKDX64BWLqXrdBm8LyIVvQIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQBlP+0xQzzGvUKpgir5 1FUNVsXKvv0RJwmYAdPom1pEst0uFYXPspfgdh1IZvApPmsp9p91p/M2gZesLVPHYqYN4KZIXQ0M gNy4YB5ksVjuTI+zBKqzuxAedIty8z/Fbsdk+BtAd/wL/ddKyHDt83lO7TqL2rxyQ5sYXU9oCPVc N8eT3mnsEfyRRQ1kNGOM7QRmttLlzdeq30tj2REZxEWksfy/ValTTRME2kHJ/kgJANEPwe598fHz vDfALNM5lrLpB37FNli58VCE2DPVTgot9fkNE7Ql4LKZ/CPdqBB2F68rvgSs9q5jAkiODRWe3FE7O aYjoR1zQZdVQJ7Nf0t+
​

Create account

PandaDoc offers three account creation methods. Select the one that fits your provisioning model:

  • Just-in-time — A user account is created the first time a user logs in via SSO. No advance provisioning required.

  • SCIM 1.1 — User accounts are created and managed remotely before login.

  • SCIM 2.0 — Full user management via SCIM 2.0, including create, update, and remove operations. Use this for group-based provisioning.

Provisioning rules

Choose how new users get their license, workspaces, and role:

  • Assign all new users with the same license, workspaces, and role: select a License, one or more Workspaces, and a Role.

  • Assign new users based on field value: under Field type, choose User's field name or Group's field name, then select the Field name (for example, Group Name). For each rule, enter the Field value and choose the License, Workspaces, and Role users with that value should get. Click Add provisioning rule to add more rules, or use the ⋮ menu to duplicate one.


If you want to configure SSO for several identity providers, you can add different configurations here:

To delete a configuration, click the three ellipses button for your configuration, then select Delete.

For further assistance with setting up SSO or managing your PandaDoc account, please contact our Support team.


IdP Side Setup

Every IdP will be a little different depending on their setup flow and default values.

The custom setup is needed for the IdPs mentioned below, refer to the articles for each different provider:

Relying party SAML 2.0 SSO URL

Entity ID

Email Attribute

Email

First Name Attribute

FirstName

Last Name Attribute

LastName


Just-in-time (JIT) provisioning

Activating a PandaDoc account without an invitation is possible if just-in-time (JIT) provisioning and SSO are enabled. JIT provisioning allows employees to become PandaDoc users automatically the first time they try to log into PandaDoc. An admin does not have to add them as a new PandaDoc user.


SCIM provisioning (automated user management)

PandaDoc supports SCIM (System for Cross-domain Identity Management) to automate user management for your organization. SCIM exchanges user identity information between your identity provider and PandaDoc, so provisioning (creating new PandaDoc users) and deprovisioning (removing users) happen automatically instead of by hand.

PandaDoc supports both SCIM 1.1 and SCIM 2.0. SCIM 2.0 adds group-based provisioning: group membership in your identity provider controls a user's role, license, and workspace access in PandaDoc, and PandaDoc keeps that access in sync as group membership changes.

What group-based provisioning does:

  • Create — When you add a user to a mapped group, PandaDoc provisions them with that group's configured license, workspace, and role. A user in several mapped groups gets access to several workspaces.

  • Update — When a user's group membership changes, PandaDoc syncs their role, license, workspace, name, and email to match.

  • Remove — Removing a user from one mapped group removes their access to that workspace only. Deleting the user in your identity provider removes them from PandaDoc entirely.

Note: A group's role options are limited to roles available across all of that group's mapped workspaces. If a group spans multiple workspaces, you can't assign it a role that only exists in one of them.

Note: PandaDoc doesn't have a deactivated-user state. Fully deprovisioning a user deletes their account rather than suspending it. Their documents and templates transfer to the workspace owner, so nothing is lost — but if they come back later, they're provisioned as a new user.

Limitations: Group custom attributes are not currently supported via SCIM.


Switching from SCIM 1.1 to SCIM 2.0

For new SCIM setups: Configure your group mappings directly in Settings > Single Sign-on. The group-based provisioning option now works end-to-end, and lets you choose the group attribute to match (Group ID or Group Name) from a dropdown, then enter the value for each rule.

Already on SCIM 1.1? You can switch to SCIM 2.0 at any time. In your SSO settings, change your SCIM configuration to SCIM 2.0 and point your identity provider at the new SCIM base URL. Copy it with Copy URL under SCIM Base URL. There's no rebuild, no re-provisioning, and no downtime.

Note: Switching isn't required. Your SCIM 1.1 setup keeps working exactly as it does today until you decide to switch.


Setting up SCIM 1.1 with Okta

Note: These steps configure SCIM 1.1. If you're setting up SCIM for the first time, use SCIM 2.0 group-based provisioning instead — see "Switching from SCIM 1.1 to SCIM 2.0" above.

  1. Go to Admin Dashboard > Applications > Browse App Catalog
    ​

  2. Search for SCIM 1.1 Test App (Header Auth) and select +Add integration
    ​

  3. Name the app "PandaDoc SCIM"

  4. Enable “Do not display application icon to users” (optional but recommended)
    ​

  5. Proceed with default sign-on options and click Done

  6. Go to the Provisioning tab and click Configure API Integration
    ​

  7. Generate a 256-bit API key using your preferred tool (e.g., RandomKeyGen)

  8. Navigate to Settings > Single Sign On within PandaDoc >

    and paste the Key in the SCIM API Token field. Make sure to add the word "Bearer" in front of the Key. Then select SCIM 1.1 under Create account, set up your Provisioning rules, and click Save changes. This will generate the SCIM Base URL.
    ​

  9. Once you obtain your unique PandaDoc SCIM URL, paste under Base URL along with the API Key generated from step 7. > Test API Credentials.

    If you receive a “SCIM 1.1 Test App (OAuth Bearer Token) was verified successfully!” message. Otherwise, ensure that there are no spaces or typos.

  10. Once you have successfully verified your connection, head over to Provisioning > Settings > To App > Click on “Edit” > Enable Create Users and Deactivate Users > checkboxes. > click Save.
    ​

  11. Save changes

  12. Test out the SCIM integration by Assigning new users or groups. This is where you can manage assignments and also remove users and groups.

Setting up SCIM 1.1 with Microsoft Entra ID (Azure AD)

You can use SCIM 1.1 with Microsoft Entra ID (formerly Azure Active Directory) to automatically provision, update, and deprovision users in PandaDoc. This helps centralize user management, improve security, and reduce administrative overhead.

With SCIM enabled, you can:

  • Automatically sync users based on group membership in Azure

  • Avoid the hassle of managing users manually

  • Ensure secure access and timely removal of users from PandaDoc

Note: Group definitions are created in Azure and synced to PandaDoc. Custom attributes are not currently supported.

  1. Log in to your Azure portal and go to Azure Active Directory

  2. Navigate to Enterprise applications under Manage

  3. Click + New application

  4. Select Create your own application

  5. Enter a name (e.g., PandaDoc SCIM) and click Create

  6. Once the app is created, go to Provisioning in the left-hand menu

  7. Click Get started

Updating an Expiring Azure SSO Certificate

If your Azure SSO certificate is expiring, follow these steps to update it:

  1. Export the new certificate from Azure in Base-64 encoded X.509 format.

  2. Open the exported file in a text editor and copy the certificate content. Remove the “-----BEGIN CERTIFICATE-----” and “-----END CERTIFICATE-----” lines.

  3. In PandaDoc, go to Settings > Single sign-on (SSO).

  4. Select your SSO configuration, then in Identity provider, click Edit certificate.

  5. Paste the new certificate and click Save changes.


Configure automatic provisioning

Note: These steps configure SCIM 1.1. For new setups, use SCIM 2.0 group-based provisioning instead — see "Switching from SCIM 1.1 to SCIM 2.0" above.

  1. Set the Provisioning Mode to Automatic

  2. Generate a 256-bit API key

    • Use your preferred encryption tool or a free tool like RandomKeyGen

  3. Navigate to Settings > Single Sign On within PandaDoc and paste the Key in the SCIM API Token field. Make sure to add the word "Bearer" in front of the Key. Then select SCIM 1.1 under Create account, set up your Provisioning rules, and click Save changes. This will generate the SCIM Base URL.
    ​


Complete SCIM setup

1. In Azure, paste the provided SCIM base URL into the Tenant URL field

2. Paste the API key into the Secret Token field.

3. Click Test Connection

If successful, you'll see a confirmation message that the connection is verified.


Final steps

  1. Assign users or groups to the application in Azure

  2. You can also manually provision a user on demand to test the setup


SSO Login scenario:

  1. Users log in with their corporate email to a PandaDoc SSO login page: https://app.pandadoc.com/sso-login/

  2. If not already authenticated, users are redirected to the corporate server or third-party identity provider login page, depending on the enterprise SSO option.

  3. Users enter their sign-in credentials.

  4. If valid, users are redirected back to PandaDoc app.

Removing Users

When you remove an employee from your company directory in your IdP, they are no longer able to access PandaDoc via SSO; however, their PandaDoc user profile is not automatically deleted. To configure automated user deletion for your PandaDoc organization, configure the attribute mapping in your IdP to disable a user in one of two ways:

  • Update > active status: "False"
    ​

    Disable a user

  • Delete user
    ​

    Delete a user

Note: If you're on SCIM 2.0 group-based provisioning, removing a user from one mapped group only removes access to that workspace — deleting them in your identity provider is what removes them from PandaDoc entirely. See "SCIM provisioning (automated user management)" above.

Alternatively, you can manually remove an employee from your PandaDoc account by going to Settings > Team and deleting the user. See more here.

Did this answer your question?