Overview
This article is for IT and security teams evaluating or auditing Appical's SSO integration — for example, ahead of a procurement review or security assessment. If you're ready to configure SSO, see SSO Configuration & Setup instead.
Authentication & protocol
Appical supports Single Sign-On via SAML 2.0 only. OpenID Connect (OIDC) is not currently supported.
SAML assertions are signed using SHA-256.
Multi-factor authentication (MFA) is not enforced by Appical directly — it's inherited from your organisation's own Identity Provider policy. If your IdP requires MFA, that requirement carries through to Appical logins.
SSO login is restricted to corporate email domains explicitly enabled for your organisation. Personal email domains (e.g., Gmail, personal Outlook) are never redirected to SSO.
Account provisioning
Appical does not auto-create accounts on first SSO login (no Just-in-Time provisioning). A user must already have an existing Appical account, created by an admin, before SSO will authenticate them. This is a deliberate control: it ensures only people your organisation has explicitly added to Appical can ever gain access, regardless of whether they hold a valid corporate email address.
Group and role assignment is handled separately from SSO (via invite, CSV import, or manual assignment) — SSO does not currently pass group or role information from your IdP.
Availability & fallback
If your Identity Provider becomes unavailable, our team can disable SSO for your organisation on request, allowing a temporary fallback to standard login while the issue is resolved. This is currently a manual process handled by our support team rather than an automated failover.
Certificate rotation handling is in active development.
📌 Important: SSO configuration changes (certificates, domains, endpoints) are currently applied by your Appical contact on your behalf rather than through self-service admin tools.
Quick reference
Capability | Supported |
SAML 2.0 | Yes |
Multiple domains per organisation | Yes |
IdP-initiated login (e.g., from an app tile in Entra ID) | Yes |
Corporate-email-only restriction | Yes |
Just-in-Time (JIT) account auto-creation | No — by design |
Attribute-based group/role assignment | No |
SCIM / automated deprovisioning | No |
Single Logout (SLO) | No |
OIDC | No |
Self-service configuration by customer IT | No |
Want to go deeper?
For the step-by-step configuration process, see SSO Configuration & Setup.
This overview is intended to answer the most common technical and security questions upfront. If your organisation requires a formal security assessment, a completed security questionnaire, a data processing agreement, or a deeper architecture-level review — particularly relevant for public sector and regulated organisations — please reach out to your Customer Success Manager to schedule a session with our security team.
👉 Let us know if this article answered your question by using the buttons below. If not, get in touch with our Support Channel for more information.