Requirements
To follow the steps in this guide, you’ll need:- Omni Organization Admin permissions
- Permissions in Rippling that allow you to:
- Create custom apps
- Assign users & groups to apps
Setup
Open the Omni authentication settings
In your Omni instance, navigate to Settings > Authentication and locate the SAML section.Leave this page open - you’ll need it to complete the setup.
Create an Omni Rippling app
- Sign into Rippling.
- Search for
Custom appin the search bar. Select the correct result. - Click Create new Custom app.
- Complete the app form:
-
Name -
Omni -
Categories -
Analytics & BI -
Upload the following logo:
- Select
Single Sign-on (SAML)orSAML and SCIM appif you intend to also configure SCIM. - Complete the single sign-on setup form:
- Leave the Metadata URL and Metadata fields empty.
- ACS URL (Assertion Consumer Service URL) - Copy and paste the Single sign-on URL value from the Omni Authentication settings (step 1)
- Service Provider Entity ID - Enter the full hostname of your Omni instance, e.g.
blobsrus.omniapp.co. Do not includehttps://.
- Leave this form open, but note the following - you’ll need it in the next step:
- Single Sign-on URL
- Issuer
- X509 Certificate
Configure Omni authentication settings
Navigate back to the Omni Authentication settings (Settings > Authentication) to complete the setup:
- Entity ID / Issuer - Copy and paste the Issuer value from Rippling
- SSO (Sign on) URL - Copy and paste the Single Sign-on URL value from Rippling
-
Certificate - Copy and paste the contents of the X509 Certificate certificate. You may need to download it from Rippling.
The certificate must include
-----BEGIN CERTIFICATE-----and-----END CERTIFICATE-----values, for example: -
Automatically provision new users on first login from this SAML provider - Toggle this setting to on if:
- You want to provision users only when they first access Omni and
- You don’t plan to set up SCIM provisioning
- Enable SAML for users - Toggle this setting to on
Complete the SSO configuration in Rippling
Navigate back to Rippling to finish configuring the custom Omni app:
- On the setup form, click Continue.
- Select Do not allow admins to sign in to the admin account.
- Skip creating any group attributes.
- Complete all other steps, clicking Visit the app when finished.
- In the app’s Settings tab, navigate to the SAML Attributes section.
-
Create the following global attributes:
Name Value Attribute 1 first_nameUser’s preferred first name Attribute 2 last_nameUser’s preferred last name