Set up SSO

Last updated: August 5, 2026

Rally supports two ways to set up Single Sign-On: Enterprise SSO (for any Identity Provider via SAML or OIDC) and Google SSO (a simpler toggle for workspaces using Google as their identity provider).

Setting up Single Sign-On requires the "Create and modify workspace settings" permission. This includes the Rally default roles Admin and Ops Manager.

  1. Select your workspace name to select Settings.

  2. From the sidebar, select Account.

  3. In the Account settings, use the SSO dropdown to choose the option that fits your company:

    • Single Sign-On (Enterprise) — for any Identity Provider, via WorkOS

    • Google SSO — for workspaces using Google as their identity provider

    • No Single Sign-On — the default, if you don't want to set up SSO


Enterprise SSO (via WorkOS)

Rally is integrated with WorkOS to support a wide range of Identity Providers, compatible with any IdP and both the SAML and OIDC protocols. Selecting Single Sign-On will redirect you to workos.com to configure SSO with your Identity Provider.

  1. Select your Identity Provider and follow the guided steps on setting up SSO. If you want to preview how the setup will look first, you can select your Identity Provider from WorkOS's integration list.

  2. After connecting Rally to your Identity Provider, you'll see a status in the Account settings card: Active (fully connected), Draft (setup started but not finished), or Inactive.

  3. If you need to make any modifications to your SSO connection, select Edit SSO Configuration. This will take you back to the WorkOS admin portal, where you can make the necessary changes.

Rally's SSO connection flow is a guided experience that will contain all the information and links you need to connect to Rally including your Entity ID and Sign-In URL, provided as you go through the setup flow.

Confirm the process is complete and active by navigating back to Settings > Account.


Google SSO

If your company uses Google as an identity provider, Google SSO is a simpler option that doesn't require the full WorkOS setup.

  1. Select Google SSO from the dropdown.

  2. Select Save Changes to confirm. Users with a matching email domain can now sign in to Rally with their Google account.