Set up Single Sign-On for Showpad Value Factory Updated October 07, 2026 07:00 SAML 2.0 Single Sign-On (SSO) gives Showpad Value Factory administrators a unified sign-in experience when they access Value Factory (value.showpad.com). This article explains what to prepare, how to configure and test the SAML connection, and how to manage it safely over time. Note: Showpad Value Factory SSO is configured separately from Showpad SSO. Even if your organization already uses SSO for Showpad, you need to configure it again for Showpad Value Factory. See how it looks You need this to succeed Plan: eOS Expert, eOS Advanced Legacy plan: Showpad Platform Enterprise Add-on: Value, Value+ Permissions: Administrator Prerequisites: A Showpad Value Factory admin account Access to your identity provider to configure a new SAML application The following information from your identity provider: Identity provider metadata XML or metadata URL Entity ID SSO URL and (optional) SLO URL X.509 signing certificate and its expiration date Identity location: NameID or a named attribute Hash algorithm (SHA-256 is preferred) Default role for just-in-time provisioning, if you plan to enable it (the role auto-assigned when a new SSO user is created in Value Factory; Marketing/Sales is recommended) The quick way Sign in to Value Factory. Navigate to Settings and select Authentication. Enable Single Sign-On (SAML 2.0) and click Save. Click + Add Configuration. Enter a friendly Name for the configuration. Select Metadata XML or Metadata URL and provide the required information Enter the SAML settings. Select a Hash Algorithm. Indicate where the user’s identity is located. Select session settings (auto-provisioning, IdP logout). Select Test Connection. Click Save Configuration. Do this step by step Enable SAML 2.0 Sign in to Value Factory (value.showpad.com). Navigate to Settings and select Authentication. Enable Single Sign-On (SAML 2.0). Select Save. Back to top Add the SAML configuration Select + Add Configuration. Enter a friendly Name for the configuration. Select the Identity Provider Metadata source: Metadata XML: Paste the XML from your identity provider, then select Parse. The remaining SAML fields are populated automatically. Metadata URL: Enter the URL from your identity provider, then select Fetch & Parse. The remaining SAML fields are populated automatically. Enter the SAML settings Entity ID: A unique identifier for the identity provider. It tells Showpad Value Factory which IdP is sending the SAML assertion. SSO URL: The identity provider's sign-in endpoint. Showpad Value Factory redirects users here when they initiate SSO login. SLO URL (optional): Single Log-Out URL. The identity provider's sign-out endpoint. When configured, logging out of Showpad Value Factory also triggers a sign-out request to the IdP. If not provided, logout only ends the local session. X.509 Certificate: The identity provider's public key certificate. Showpad Value Factory uses it to verify that SAML responses actually came from your IdP and haven't been tampered with. Select a Hash Algorithm: SHA-1: An older hash algorithm. Still supported but considered less secure. Use only if your identity provider does not support SHA-256. SHA-256: The recommended hash algorithm. More secure than SHA-1 and supported by all modern identity providers. Specify the user’s identity location: Identity resides in the NameID element of the subject Identity resides in the Attribute element. If selected, enter the attribute name. Select session settings: Auto-provision accounts for new users: Automatically creates value.showpad.com accounts when users sign in via SSO for the first time. Select a default role for new users from the dropdown menu. Log out from IdP when logging out from Showpad Value Factory: Signs users out of the identity provider when they log out of the app. Click Test Connection to verify your selections. Click Save Configuration. Back to top Maintain the configuration Certificate renewal Plan certificate renewal before the expiration date shown in your configuration. Replace the certificate, run Test Connection, save, and test again in a private browser session. Adding new administrators When you add a new administrator, confirm they have a linked SSO identity before they attempt to sign in. See 3. Configure and manage administrator access and roles. Back to top Troubleshooting Issue Solution Test Connection fails Check the Entity ID, SSO URL, certificate, identity source, and attribute name. Use SHA-256 if your identity provider supports it. Check the identity provider logs for the same timestamp to compare errors. The user is not recognized Compare the SAML identity value with the email or identity stored for the administrator account. Review the NameID format or the selected attribute. An administrator lost access Use an administrator who still has credentials or a working SSO identity. Re-enable credential sign-in while you correct the configuration. If no administrator can sign in, contact Showpad Support. A certificate is expiring Replace the certificate before its displayed expiration date. Run Test Connection, save, and test in a private browser session. Do not send certificates with private keys when escalating to support. When escalating an issue, include the configuration name, error text, timestamp, identity provider name, and redacted SAML diagnostic details. Related articles Customize branding for a value model Understand value models