Identity Providers
Configure SSO and user provisioning with your identity provider
Integrate Verkada Command with your organization's identity provider (IdP) for Single Sign-On (SSO) and automated user provisioning.
Supported providers
Which method should I use?
Want the most secure option? Use OIDC + Enterprise Controlled Encryption
Need automated user management? Add SCIM provisioning to sync users from your IdP
IdP only supports SAML? Follow the generic SAML setup instructions below
You need Organization Admin permissions to set up SSO.
Generate client-ID
Go to Verkada Command > All Products > Admin.
Under Login & Access, select Single Sign-On (SSO).
Click Add New.
You should see your client ID and the fields to enter into your IdP:
Client ID:
US orgs:
https://vauth.command.verkada.com/saml/sso/<client-ID>EU orgs:
https://saml.prod2.verkada.com/saml/sso/<client-ID>AUS orgs:
https://saml.prod-ap-syd.verkada.com/saml/sso/<client-ID>
Reply ID:
US orgs:
https://vauth.command.verkada.com/saml/sso/<client-ID>EU orgs:
https://saml.prod2.verkada.com/saml/sso/<client-ID>AUS orgs:
https://saml.prod-ap-syd.verkada.com/saml/sso/<client-ID>
Sign-on URL:
US orgs:
https://vauth.command.verkada.com/saml/login/<client-ID>EU orgs:
https://saml.prod2.verkada.com/saml/login/<client-ID>AUS orgs:
https://saml.prod-ap-syd.verkada.com/saml/login/<client-ID>
Upload SAML XML metadata
After configuring your IdP, you'll receive an XML metadata file. Upload it to Command.
In the Verify Metadata section, click Add Domain.

If the login tests fail, review your metadata file and associated domains.
Common error: app_not_configured_for_user — This can happen when your browser has cached app access. Use an incognito browser or clear your cache and retry.
Once verified, toggle on Require SSO to enforce SSO sign-in.

Enforce SSO
After configuring SAML, you can enable SSO Enforcement:
Anyone using the configured email domain must go through SAML to sign in
Provides greater control over user access
If SAML has issues, users cannot sign in until resolved or enforcement is disabled
Need help?
See SCIM Token Management for provisioning configuration.
Last updated
Was this helpful?

