Requirements
To follow the steps in this guide, you’ll need:- Omni Organization Admin permissions
- Permissions in Rippling that allow you to:
- Create custom apps
- Assign users & groups to apps
Setup
1
Open the Omni authentication settings
In your Omni instance, navigate to Settings > Authentication and locate the SAML section.
2
Create an Omni Rippling app
- Sign into Rippling.
- Search for
Custom appin the search bar. - Select Create new Custom app.
- Complete the app form:
-
Name -
Omni -
Categories -
Analytics & BI -
Upload the following logo:
- Select Single Sign-on (SAML), or SAML and SCIM app if you intend to also configure SCIM.
- Complete the single sign-on setup form:
- Leave the Metadata URL and Metadata fields empty.
- ACS URL (Assertion Consumer Service URL) - Copy and paste the Single sign-on URL value from the Omni Authentication settings (step 1)
- Service Provider Entity ID - Enter the full hostname of your Omni instance, e.g.
blobsrus.omniapp.co. Do not includehttps://.
- Leave this form open, but note the following - you’ll need it in the next step:
- Single Sign-on URL
- Issuer
- X509 Certificate
3
Configure Omni authentication settings
Navigate back to the Omni Authentication settings (Settings > Authentication) to complete the setup:
- Entity ID / Issuer - Copy and paste the Issuer value from Rippling
- Single Sign-on URL - Copy and paste the Single Sign-on URL value from Rippling
-
Certificate - Copy and paste the contents of the X509 Certificate certificate. You may need to download it from Rippling.
The certificate must include
-----BEGIN CERTIFICATE-----and-----END CERTIFICATE-----values, for example: -
Automatically provision new users on first login from this SAML provider - Toggle this setting to on if:
- You want to provision users only when they first access Omni and
- You don’t plan to set up SCIM provisioning
- Enable SAML for users - Toggle this setting to on
4
Complete the SSO configuration in Rippling
Navigate back to Rippling to finish configuring the custom Omni app:
- On the setup form, click Continue.
- Select Do not allow admins to sign in to the admin account.
- Skip creating any group attributes.
- In the app’s Settings tab, navigate to the SAML Attributes section.
-
Create the following global attributes:
Clicking the “test now” button at this point will yield an error, as Rippling initially sets the SAML SSO as IdP-initiated. You will change this to SP-initiated in the next step.
5
Configure service provider (SP) initiated flow
- In the Custom app’s Settings > Advanced SAML Settings, enable Application only supports login initiated from the application, also referred to as SP initiated flow.
- In URL to trigger SP-initiated flow, enter the URL of your Omni instance, e.g.
https://blobsrus.omniapp.co/.
6
Assign users and groups
In Rippling, assign users and user groups to the custom Omni application.
7
Test the setup
Test your SAML setup by logging out of Omni. On the Omni login page, you should see a Log in with SAML button. Click the button to log in using SAML.If the setup is successful, finish the setup by rolling out SAML authentication to the rest of your organization.

