Configure SSO from Salesforce
Salesforce can act as a single sign-on (SSO) provider to hundreds of web and mobile applications using standards such as SAML, OAUTH, and OpenID Connect.
PurelyHR supports SAML based SSO protocol. Follow these step-by-step instructions to configure SSO to PurelyHR.
Pre-requisites
- Need SAML-enabled admin account for PurelyHR
- Access to Salesforce as an administrator.
Step 1: Setup Salesforce as a SAML Identity Provider(IdP)
- Follow this link to setup your Salesforce org as a SAML Identity Provider.
- Download the Salesforce SAML IdP certificate. You will need it later in the below instructions.
Step 2: Configure PurelyHR
- Sign in to your PurelyHR admin account.
- Navigate to:
- Your Dashboard → SSO Settings
- Under Generic SAML Connector, you'll find:
- IdP Provider Settings
- PurelyHR ACS URL
- Enter the following:
- x.509 Certificate: Paste your Salesforce Identity Certificate Content.
- IdP Issuer:
https://yoursalesforcedomainname.my.salesforce.com
(Example: https://identitydemo.my.salesforce.com) - IdP Endpoint URL: https://yourdomainname.my.salesforce.com/idp/endpoint/HttpRedirect
- Click on Save Changes.
Step 3: Configure Salesforce Connected App
- Login as Administrator and go to:
- Setup → App Setup → Create → Apps
- Under Connected Apps, click New.
- Fill in:
- Connected App Name (API Name auto-populates)
- Logo Image URL (choose sample or provide your own)
- Contact Email
- Under Web App Settings:
- Enable SAML
- Entity ID: purelyhr.com
- ACS URL: Use PurelyHR ACS URL and append your CompanyID:
https://www.purelyHR.com/cpanel/sso/consume.aspx?company_id=YOURCOMPANYIDHERE - Subject Type: Federation ID
- Name ID Format: Default (unspecified)
- Issuer: Default
- Service Provider Certificate: Leave unselected
- Save the settings.
- Go to Manage Apps → Connected Apps:
- Select your app.
- Assign profiles/permission sets for users.
- Copy the IdP-Initiated Login URL for testing.
- Edit the Start URL with the copied link and save.
Step 4: Test SSO
Use IdP-Initiated Login URL or go to Salesforce App Launcher:
- Click on the PurelyHR icon.
- A PurelyHR session will start upon successful SSO.
Important: PurelyHR does NOT support SP-initiated SSO.