SAML SSO

redirect.pizza can connect directly with your IdP to enable SSO via SAML2. This guide provides the necessary information for configuration.

Note: SAML SSO is available from our Business plan and up.

Setting up

Open SAML SSO in redirect.pizza. You'll find your Entity ID, ACS URL, SLS URL, and signing certificate links there.

Navigate to your identity provider and set-up your SSO connection with the Entity ID & ACS URL as defined here.

Set the following options if available:

  • Name ID format: EmailAddress
  • Signed Assertions: Yes
  • Encryption: Preferred. Download our current certificate.

Uploading the metadata XML file

Download your IdP's metadata XML file and upload it under the same segment. We'll extract the necessary details automatically. By default, the integration is set up for a single domain. If you need multiple domains (or another one than set by default), support can assist.

Once the metadata XML is uploaded, the SAML SSO connection becomes active.

Authentication

When SAML SSO is activated, users may authenticate through their IdP or via redirect.pizza. When a domain is detected in the email address, we'll prompt the user with the ability to login directly with SAML SSO.

SAML SSO login

Access

Only users that have been invited via redirect.pizza may access the account.

You can invite new users under More -> Users. They will receive an one-click link which can be used with SSO to activate their account.

Single logout

redirect.pizza supports SAML Single Logout (SLO), allowing users to be logged out via your IdP. The SLO URL can be found in your SAML settings under More -> Settings. Use this URL in your identity provider to configure IdP-initiated logout.

Certificate rotation

redirect.pizza automatically renews its SAML signing certificate. When a new certificate is issued, both the current and expiring certificates stay valid for about 60 days so you have time to update your Identity Provider.

During that window you'll get an email, and the SAML SSO page shows links to both certificates:

The easiest option is to re-import your SP metadata from the metadata URL on the SAML SSO page. That picks up both certificates for you.

After the cutoff, only the current certificate remains valid. If your IdP still has only the old one, SAML sign-in will stop working until you update it.

More articles

Walkthroughs
GoDaddy: Forwarding with HTTPS support
Network Solutions: Forwarding with HTTPS support
Namecheap: Forwarding with HTTPS support
Hover: Forwarding with HTTPS support
TransIP: Forwarding with HTTPS support
Cloudflare: Forwarding with HTTPS support
Amazon Route 53: Forwarding with HTTPS support
NS1: Forwarding with HTTPS support
DigitalOcean: Forwarding with HTTPS support
Google Cloud DNS: Forwarding with HTTPS support
EuroDNS: Forwarding with HTTPS support
Azure DNS: Forwarding with HTTPS support
DNS Made Easy: Forwarding with HTTPS support
Freenom: Forwarding with HTTPS support
Mijndomein: Forwarding with HTTPS support

Domain redirects delivered hassle-free

Get started right away

  • Free plan
  • No creditcard required

redirect.pizza has all your favorite ingredients

Analytics

Who is still visiting those old domains? Gain valuable insight with detailed statistics and find out where the hits are coming from.

Learn more

API

Connect your software to automatically create redirects via our API. Automation makes your life easier.

Learn more

Destination Variables

You control how we handle your destination URL. Want to include your domain extension as a query string parameter? No problem.

Learn more

Dynamic destinations

Steer your traffic to different destinations, based on rules you define.

Learn more

Path forwarding

Keep the original path and keep it in the destination for a smooth domain migration and keeping your SEO game intact.

Learn more

Query Parameter Forwarding

Forward query parameters found on the source URL to the destination.

Learn more

Multiple Redirect Types

Choose the status code that works for you. Choose 301/307 (permanent), 302/308 (temporary) or frame your destination.

Learn more

Team management

Doing things all by yourself isn't much fun. Invite your co-workers to manage the redirects and work as a team.

Learn more

Automatic DNS

Integrate directly with your DNS provider, and apply the DNS changes from one platform.

Learn more

QR code generator

Create a QR code that you can use for marketing purposes. You can change the destination anytime after printing.

Learn more

Import & Export

Manage your redirects without losing precious time. Import and export redirects in our UX-friendly interface.

Global edge network

Redirecting in a blink of an eye; processing millions of request per hour in milliseconds.

Learn more

Broken destination monitor

Automatically checking your destinations to ensure it's reachable for everyone.

Learn more

Privacy First

We're based in Europe and are fully compliant with GDPR. Privacy-first!

Learn more

Wildcard subdomains

For when your domain utilizes a lot of different subdomains. Cover all subdomains with a single redirect.

Learn more

Tags

Group your redirects by adding tags. Keep everything organized and easy to find.

Bulk actions

Want to apply the same action for multiple redirects in one go? Do yourself a favor and start using bulk actions.

Dark mode

Give your eyes some well deserved rest by using the dark mode. Sync with your system or choose manually.

HSTS

Enable HSTS (HTTP Strict Transport Security) on team or domain level for an extra layer of protection.

Learn more

Change Destination Anytime

Once you're set up, you can change the destination URL anytime you want, and see the change in real-time.

Two-Factor Authentication

Secure your account with TOTP two-factor authentication. Scan the QR code, setup your app of choice, and you're safe(er).

Learn more

IDN Support

Add international hostnames with non-Latin characters. We ❤ that.

Support

Chat away! We're happy to help set up your account and answer your questions.