Skip to content
Oh Dear

Who still has access?

Single sign-on.

Your agency watches many client sites. A former contractor should not still have access to their monitors. Connect Oh Dear to Okta, Microsoft Entra ID, Google Workspace or another SAML 2.0 provider, then require SSO for everyone except the team owner.

10-day free trial · No credit card required · Every feature included

Any SAML 2.0 provider SSO on every plan
  • Bitmovin
  • HBO Nordic
  • Obsidian
  • Laravel
  • Fathom Analytics
  • PHP 8
  • Stanford University
  • Takeaway.com
  • IGN
  • VRT NWS
  • spatie

Access, not monitoring

Oh Dear watches your sites. SSO decides who gets in.

Oh Dear watches your client sites from outside your stack. Single sign-on decides who can see and change those monitors, across staff and contractors.

Removing access to client monitors Illustrative

A password per service

Offboarding
Revoke access in every tool, one by one
New starter
Another invite, another password to remember
Audit
Check accounts and tokens in each service

One identity in your IdP

Offboarding
Unassign in the IdP to stop new SSO sign-ins; remove from the Oh Dear team to revoke tokens
New starter
The first IdP login creates the account when JIT is on
Audit
New SSO sign-ins follow IdP assignment; team membership stays separate

With enforcement on, unassigning someone in your IdP blocks a new SSO sign-in. Existing SSO sessions last 24 hours at most. Remove the person from the Oh Dear team as well to revoke their team-scoped API tokens. How offboarding works.

Bring your own identity

Works with the IdP you already run.

Oh Dear speaks SAML 2.0. Pick your provider for a guided setup, or connect any other provider that speaks the protocol. Each team connects one identity provider.

Guided setup

  • Okta
  • Microsoft Entra ID
  • Google Workspace
  • OneLogin
  • JumpCloud

Also works

  • Auth0
  • PingFederate
  • Any SAML 2.0 provider

NameID format EmailAddress · RSA-SHA256 or stronger · SHA-1 signatures are rejected

Set up in four steps.

  1. Verify Prove you own the domain with a DNS TXT record. One team per domain, and no public email domains.
  2. Connect Copy the ACS URL, Entity ID and SP metadata into your IdP. Paste back its metadata URL, or enter the Entity ID, SSO URL and X.509 certificate by hand.
  3. Test Run the test login. SSO cannot be enabled for the team until the test passes.
  4. Enable Switch SSO on. Unlinked non-owner members on a verified domain get a one-time linking email, valid for 72 hours.
Matt Puttick
Oh Dear is user-friendly, easy to set up and onboard users, and is accessible to non-techies.

Matt Puttick, Product Owner at CityFibre

A new team member signs in with the company account they already have.

One login page

Your team enters an email. Oh Dear does the routing.

No separate SSO portal and no special URL to bookmark. Oh Dear looks up the email domain and shows each person the right way in.

Email-first login

SSO required Members of an enforced team are sent to your IdP automatically.
SSO available The password field appears, with a link to sign in with SSO.
No SSO on the domain The password field appears as usual.
Failed SSO lookup The password field appears at once. No dead end.

Require SSO

Everyone but the owner Password login is blocked, admins included. IdP only.
Before you enforce A preview shows linked and unlinked members.
The team owner Keeps password access as break-glass.

Provisioning

Just-in-time, when enabled The first IdP login creates the account as a member.
Existing members Unlinked non-owners on a verified domain get a one-time linking email, valid for 72 hours.
Auto-join, when enabled Existing Oh Dear users on a verified domain join the team on their first IdP login.

Enforce with a safety net

Protect access to every client monitor.

When a contractor leaves an agency, one Oh Dear team may still cover many unrelated client sites. Require SSO for everyone but the owner, remove leavers from the team, and keep owner break-glass for an IdP outage.

Break-glass and ownership

  • Owner break-glass. The team owner always keeps password login, and break-glass use is logged.
  • Local two-factor. Still applies to password and break-glass logins when set up. Skipped for SSO sessions, where the IdP enforces MFA.
  • Domain proof. DNS TXT verification before SSO. One team per domain, and no public email domains.
  • Certificate rotation. Two certificates are accepted during a rotation. The owner is notified 30, 14 and 7 days before expiry.

Protocol hardening

  • Signatures. RSA-SHA256 or stronger. SHA-1 is rejected.
  • Audience. Assertions must be addressed to Oh Dear's SP Entity ID.
  • Replay. Assertion IDs are cached for 15 minutes, so a reused assertion is blocked.
  • NameIDs. Transient identifiers are rejected. Only stable subjects are accepted.
  • Sessions. 24 hours at most on enforced teams, scoped to the team.
  • API tokens. Independent of SSO. They survive enabling and enforcing. Removing a member revokes their tokens scoped to the team.

IdP-initiated login is off by default, so the flow starts from Oh Dear's own login page. Turn it on only if your organization requires it.

No feature tiers

Every check.
Every plan.

SSO is on every plan, next to Oh Dear's website checks. You pay for the number of sites you monitor, not for the security features you need.

Start with everything on.

Try SSO alongside uptime, DNS, domain monitoring and the rest of the website-health toolkit.


  • SSO on every plan
  • Every monitoring feature included
  • Plans scale by monitored site count
  • No credit card required
Start a free trial

10-day free trial. No credit card.

Before the first login

Questions about single sign-on.

What SSO controls, how it connects, and where it ends.

What is SSO in Oh Dear?

Team sign-in through your identity provider. Oh Dear supports SAML 2.0, so members sign in with their existing company account and you manage access in one place. SSO decides who gets into Oh Dear. It is not a monitoring check. Each team connects one identity provider.

Which identity providers work with Oh Dear?

Any SAML 2.0 provider. The setup screen has guided steps for Okta, Microsoft Entra ID, Google Workspace, OneLogin and JumpCloud. The docs also cover Auth0 and PingFederate. Any other provider that speaks SAML 2.0 connects through the generic setup.

How does SSO setup work?

Verify your domain with a DNS TXT record. Connect your identity provider with its metadata URL, or enter the Entity ID, SSO URL and X.509 certificate by hand. Then run a test login, which is required before SSO can be enabled. After that, unlinked non-owner members on a verified domain get a one-time linking email that expires after 72 hours.

What happens when someone leaves the team?

Unassign them from the Oh Dear app in your identity provider. With enforcement on, that blocks new SSO sign-ins. On an enforced team, existing SSO sessions last 24 hours at most. Also remove them from the Oh Dear team, which revokes their team-scoped API tokens.

Can I require the whole team to use SSO?

Yes, except the team owner. Enforcement blocks password login for every other member, admins included. Before you switch it on, Oh Dear shows which members are linked and which would lose access until they link. The owner keeps password access as break-glass, and break-glass use is logged.

Do new team members still need invites?

Not with just-in-time provisioning on: the first sign-in through your identity provider creates their Oh Dear account as a member. A separate auto-join setting covers existing Oh Dear users. You can change their role to admin or guest afterwards.

Does SSO change two-factor authentication?

For SSO sessions, Oh Dear skips its own two-factor step and your identity provider enforces MFA. Password logins, including owner break-glass, still ask for two-factor when it is set up.

What if our identity provider goes down?

The team owner can sign in with their password as break-glass. On an enforced team, other members have to wait for the identity provider to recover. Existing SSO sessions keep working until their 24-hour limit.

Are API tokens affected by SSO?

No. Tokens authenticate on their own, so CI/CD pipelines and automations keep working when SSO is enabled or enforced. Removing a user from the team revokes their tokens scoped to that team.

Is SSO an enterprise add-on?

No. SSO is on every plan, because security should not be the thing you upgrade for.

See all other FAQ items

Get started

Start monitoring the sites behind one sign-in.

Verify your domain, connect your IdP, and require SSO for your team. Every feature on. No credit card.