Harvestr supports four authentication methods: email/password, Google SSO, Microsoft SSO, and SAML SSO. You choose which ones your workspace accepts.
Prerequisites
Any paid plan for Google and Microsoft SSO — Elite for SAML SSO
An Editor account
Access to your Identity Provider's configuration, for SAML
Turn methods on and off
Go to Organization settings.
You'll see the four methods listed.
Toggle each one on or off. SAML SSO has its own setup, covered below.
Before you disable email/password, make sure your chosen SSO method works for every teammate — including the Owner. Otherwise you lock yourself out of your own workspace.
Multiple domains with Google and Microsoft SSO
By default only the domain of the email that created the workspace is authorized. If your team spans several domains, contact support and we'll add them.
SAML SSO with a specific provider
Step-by-step guides:
SAML SSO with any other provider
In your IdP admin console, create a new SAML 2.0 application — often labelled "Custom SAML" or "SAML 2.0 Connector".
Set the Service Provider parameters from Harvestr's SAML SSO settings: the ACS URL (Assertion Consumer Service) and the SP Entity ID.
Set the NameID to the user's email — that's what Harvestr matches on.
Export the IdP metadata (XML) or copy its metadata URL, and upload it into Harvestr's SSO configuration.
Assign the SAML app to the right groups or users in your IdP, so only authorized people can sign in.
Your team can now authenticate into Harvestr through your corporate identity provider.
Troubleshooting: the HTTP-Redirect binding
Harvestr sends its SAML AuthnRequest using the HTTP-Redirect binding. Your IdP must expose a SingleSignOnService endpoint supporting it.
Check your exported metadata for a line like:
<md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://your-idp.com/sso/redirect-endpoint" />
If it isn't there, enable or declare the Redirect binding in your IdP's SAML application settings, re-export the metadata, and upload it again.
This is the most common reason a SAML setup fails silently — worth checking first.
Still stuck? Message us and we'll look at your metadata with you.
