Okta
Entra ID
Google
OneLogin
JumpCloud
Any SAML 2.0

Single Sign-On (SSO)

Your team already has an identity provider. Why manage another set of passwords?

Connect Oh Dear to your organization's IdP and let your team sign in with the credentials they already use. Centralized access control, automatic provisioning, and one less password to worry about.

Start monitoring

10 day free trial
No credit card required

Centralized control
Manage access from your IdP
Automatic provisioning
New team members get access instantly
Included in every plan
No enterprise tier required
01

One login for your entire team

Centralized access through your identity provider

When your team grows, managing individual passwords becomes a liability. Someone leaves, and you scramble to revoke access across a dozen services. Someone new joins, and they need yet another password to remember.

With SSO, your team signs into Oh Dear using the same credentials they use for everything else. Disable someone in your IdP, and they lose access to Oh Dear automatically. No shared passwords, no forgotten accounts, no access gaps.

Available on every plan, because security shouldn't be a premium feature.

Okta
Microsoft Entra ID
Google Workspace
OneLogin
JumpCloud
Any SAML 2.0
02

Works with the IdP you already use

SAML 2.0 compatible with every major provider

Oh Dear supports any SAML 2.0 identity provider. We've built guided setup flows for the most popular ones, so configuration takes minutes, not hours.

Okta, Microsoft Entra ID (Azure AD), Google Workspace, OneLogin, JumpCloud, Auth0, PingFederate - we have step-by-step instructions for each. Using a different SAML 2.0 provider? That works too.

We provide your SP metadata URL, Entity ID, and ACS URL. Copy them into your IdP, paste your IdP details back, and you're done. Test the connection before enabling it for your team.

Step 1
User enters email address
Step 2
SSO domain? Redirect to IdP. Otherwise, show password field.
Done
Authenticated and in the dashboard
03

Email-first login

Seamless for both SSO and password users

When your team members visit the login page, they enter their email address. If their domain has SSO configured, they're redirected to your IdP automatically. Non-SSO users see the password field as usual.

No separate SSO login page, no special URLs to bookmark. Your team just enters their email and the right thing happens.

If you want to go further, you can enforce SSO for all non-owner team members. Password login gets blocked entirely for those users, so there's no way to bypass your organization's authentication policy.

SSO enforcement
Block password login for non-owners
Owner break-glass
Password access always available for owners
DNS domain verification
Prove ownership before enabling SSO
04

Enforce SSO, keep a break-glass

Security policies with a safety net

Enforce SSO to require all non-owner team members to authenticate through your IdP. Password login is blocked, API tokens keep working, and your security policy is fully applied.

Team owners always retain password access as a break-glass mechanism. If your IdP goes down, you can still get into Oh Dear. Every break-glass login is logged for audit purposes.

Domain verification via DNS proves your organization owns the email domain before SSO can be enabled. No one can hijack your team's authentication by claiming a domain they don't control.

Existing team members receive a one-time linking email to connect their account to their IdP identity. No silent account linking by email alone.

Stop worrying, start monitoring

Start a no-strings-attached 10-day free trial. You're all set in less than a minute.
(No credit card needed.)

Not convinced yet? Need help?
Get in touch via [email protected].

SHA-256+ signature validation Weak algorithms rejected
Audience restriction enforcement Assertions scoped to your SP
Replay protection Same assertion cannot be reused
Certificate rotation Dual-cert support for zero-downtime
24-hour session lifetime Re-authentication enforced daily

Built on SAML 2.0

Industry-standard enterprise authentication

SAML 2.0 is the industry standard for enterprise single sign-on. It's supported by every major identity provider and trusted by organizations worldwide.

Certificate rotation is handled gracefully. Upload a secondary certificate before your primary expires, and Oh Dear validates against both during the transition. We'll notify you at 30, 14, and 7 days before expiry.

Security hardened. SHA-1 signatures rejected. Audience restriction enforced. Replay protection active. Transient NameIDs blocked. Every assertion is validated against a strict set of rules before we trust it.

API tokens are unaffected. Your CI/CD pipelines and automation scripts keep working regardless of SSO session state. Tokens are revoked only when a user is removed from the team.

Want the full setup guide?

Step-by-step instructions for Okta, Microsoft Entra ID, Google Workspace, and more. Everything you need to get SSO running.

Wait, there's even more

ssl shield

Continuous certificate monitoring

SSL certificates are essential in website security. We check all your certificate expiration dates & alert any change we detect.

Explore continuous certificate monitoring

Performance monitoring

We provide highly detailed performance monitoring and insights. We'll notify you as soon as we detect your website is getting slow.

Explore performance monitoring

Fast and insightful notifications

Get notified instantly as soon as we detect an issue or an important change. Enable any channel you use, you're in full control.

Explore fast and insightful notifications

Scheduled task monitoring

Your cron jobs (Linux) and scheduled tasks (Windows) are the heart of your data processing. We can monitor every single one of them.

Explore scheduled task monitoring
Broken links detection interface base view Broken links detection interface showing error details Broken links detection interface showing additional errors

Broken page & mixed content

We crawl and index your entire website, just like Google. As soon as we detect a broken link on your site we will let you know.

Explore broken page & mixed content
dns dropwdown

DNS record monitoring

Receive a notification whenever your DNS records are modified - intentionally or maliciously - so you can act and verify faster.

Explore dns record monitoring
DISK SPACE
api
screen
arrow 1 arrow 2
arrow 3 arrow 4
REQUEST QUEUE
server

Application health monitoring

A lot can go wrong inside your app and server. Disk space may fill up, or the database may go down. We'll notify you when something is off.

Explore application health monitoring
takeaway.com
takeaway.com logo
Today
No incidents on this day

Beautiful public status pages

In times of crisis, a public status page allows you to communicate to your clients. We'll host your status page so it's always available.

Explore beautiful public status pages
Monitor
Performance
Uptime
Certificate
laravel.com logolaravel.com
272ms
Up
Ok
ign.com logoign.com
272ms
Up
Ok
takeaway.com logotakeaway.com
272ms
Up
Ok

Website uptime monitoring

When your website goes down we'll let you know instantly. Now you can act before your or your client's brand reputation takes a hit.

Explore website uptime monitoring
⚠️ Domain expired / transfer allowed
takeaway.com

Domain monitoring

We can check how long your domain is still registered. If your renewal date is close, we'll notify you. This will avoid you losing your domain.

Explore domain monitoring
Lighthouse

Lighthouse SEO monitoring

We track the speed & performance of your website over time. If we detect your website is suddenly slower, we'll let you know.

Explore lighthouse seo monitoring
Sitemap

Sitemap monitoring

Elevate your SEO strategy and optimize your site. We analyse your sitemap health and check every URL for broken links.

Explore sitemap monitoring

Describe what you want to monitor

AI monitoring

Use AI to verify anything you want on your websites and services with Oh Dear's AI monitoring feature.

Explore ai monitoring
Sitemap

Port scanning monitoring

Port scanning monitoring keeps an eye on important ports that should either be open or closed. Get notified when a port changes state unexpectedly.

Explore port scanning monitoring
Sitemap

DNS blocklist monitoring

DNS blocklist monitoring helps you stay off spam and ad-block lists. Get notified when your DNS is blocked by a blacklist.

Explore dns blocklist monitoring
mobile preview

Start monitoring instantly

Start a no-strings-attached 10-day free trial. You're all set in less than a minute.
(No credit card needed.)

Not convinced yet? Need help?
Get in touch via [email protected].