For lawyers
Configure SAML SSO
Wire up your identity provider to LeyApp so colleagues sign in with your company credentials.
- 5 steps
- ~5 min
- Requires a LeyApp account
Anyone with this link can open the walkthrough — no account is needed to watch the demo.
What this walkthrough covers
- 1
Service provider info
Copy the ACS URL and Entity ID from this card. Paste them into your IdP when you create a SAML application for LeyApp.
- 2
Paste IdP metadata
Export the SAML metadata XML from your IdP (Okta, Google Workspace, Microsoft Entra ID, etc.) and paste it here. You can also paste a hosted metadata URL instead.
- 3
Confirm your domains
SSO routes only users whose email matches one of your firm's verified domains. Make sure all the domains you want covered are listed.
- 4
Save the configuration
Click Configure provider. LeyApp validates the metadata and activates the SSO provider for your firm in Supabase Auth.
- 5
Pick an enforcement level
Optional means SSO and password both work. Preferred makes SSO the default. Required blocks password logins on your domain — test with non-owner accounts before enabling.
Related help articles
Single Sign-On (SSO) for your firm
Configure SAML so your team logs in with your existing identity provider.
Verifying your firm
Upload bar-association proof and firm registration so clients see the verified badge.
Security & Privacy
Learn about passkeys, two-factor authentication, login security, and how LeyApp protects your data.