Pellio

Set up single sign-on and SCIM

Paid add-onUpdated October 10, 2026
On this page

Single sign-on and SCIM come with Pellio Drive. They apply to signing in to your whole Pellio workspace, not just Drive. Owners and admins set them up in Settings → Security, in the Single sign-on card. Okta, Microsoft Entra ID, Google Workspace and any other SAML or OIDC provider work.

Add a connection

  1. Click Add a connection and choose the Protocol: SAML or OIDC.
  2. Enter your Email domain. People with addresses there sign in through this provider.
  3. For SAML, paste the Identity provider metadata (XML), or fill in the Sign-in URL (SSO URL), Issuer (entity ID) and Signing certificate. For OIDC, enter the Issuer URL (Pellio reads the rest from it), Client ID and Client secret.
  4. Click Add connection, then copy the values Pellio shows into your identity provider: the ACS (reply) URL and Entity ID (audience) and metadata URL for SAML, or the Redirect URI for OIDC.

For SAML, send the person’s email address as the attribute email and their name as displayName (or givenName and surname).

Verify your domain

A new connection shows Domain not verified, and nobody signs in through it until it’s verified. Add the TXT record shown (Name and Value) at your DNS provider, then click Check DNS. Once it’s found, the connection shows Verified. DNS changes can take a while to show up, so check again later if needed.

Signing in

On the Pellio log-in page, people click Sign in with SSO, enter their work email and click Continue with SSO. Their identity provider signs them in, and the first time they join your workspace.

Require single sign-on

Once a domain is verified, you can turn on Require single sign-on. Everyone at your verified domains must then sign in through your identity provider. Owners can still use their password, so you can’t be locked out. Remove on a connection lets those people sign in with a password or Google again.

Directory sync (SCIM)

Under Directory sync (SCIM), copy the SCIM base URL and click Make a SCIM token. Copy the token straight away: Pellio shows it only once. In your identity provider’s SCIM provisioning settings, enter the base URL and the token. Assigning someone the Pellio app adds them to your workspace; unassigning or deactivating them removes them. Owners are only ever changed in Pellio.

New token replaces the token (the old one stops working at once) and Turn off SCIM stops directory sync. People SCIM adds are workspace members; to give them Drive, an admin turns them on under Members on the Drive page.

Was this article helpful?

Still stuck?Send us a message and a person will get back to you.