What this does
This feature requires visitors to log in through your organization's SAML identity provider before they can view a published project. It controls who can view your live, published content.
This is different from team SSO, which controls who can log in to the Vev editor to build and publish. If you are looking for that instead, see Set up single sign-on (SSO) for your team.
When enabled for a hosting, authentication applies to all projects published under that hosting address. A hosting can have multiple SSO setups configured, so different projects under the same hosting can be gated by different identity providers [VERIFY: that the provider choice is made per project].
You can also make authentication enabled by default, so projects published under the hosting are protected automatically. You can turn it off for individual projects if you need an exception.
Who can do this
Enabling SSO on published pages requires:
The Owner or Admin role on the account
An account on the Organization plan
When to use it
Use this feature when an internal report, a partner-only campaign page, or a client engagement needs to stay behind your identity provider rather than open to anyone with the link. Because a hosting can hold multiple SSO setups, you can run separate client engagements under the same hosting, each pointed at that client's own identity provider. You no longer need a separate hosting per engagement, though you can still split engagements across hostings if you prefer to keep them fully apart.
How to set it up
Step 1: Open hosting settings
Go to Account settings.
Click Hosting in the left panel.
Find the hosting you want to configure and open its settings.
Step 2: Configure your SAML provider(s)
Scroll to Authentication on published pages.
If you have not set up a SAML provider yet, click Configure SAML provider. You will be redirected to Account Security to complete the setup with your identity provider.
You can configure more than one SAML provider and make them all available on the same hosting.
Once SAML is configured, return to the hosting settings page.
Step 3: Enable authentication
Select the SAML provider you want to use from the dropdown. If you have configured several, choose the one that should apply.
Authentication is enabled immediately for all projects published under that hosting.
To keep new projects protected automatically, set authentication to be enabled by default for the hosting.
Step 4: Test access
Open the published project in a private or incognito browser window and confirm that you are prompted to log in through the identity provider before the content loads.
Make an exception for a single project
Open the project's Publish dialog.
Find the publish item.
Click the authentication icon next to it to disable SSO for that project only, or to switch it to a different SAML provider if the hosting has more than one configured.
Good to know
Vev does not manage individual user access for this feature. Anyone with a valid login to your SAML provider can view the protected pages. Granting and revoking access happens in your identity provider, not in Vev.
A project is gated by one identity provider at a time; visitors are not offered a choice of login methods.
This feature is only available on standard Vev hosting (vev.site domains) and the Vev staging domain. It is not available on custom domains or other custom hosting setups.
If you disable authentication, the login screen may stay visible for a short time due to caching before it clears.
Need more help
If you run into an issue setting up SSO on published pages, reach out to the Vev team:
In-app chat: click the chat bubble in the bottom corner of your Vev account
Email: support@vev.design
Support tickets: help.vev.design/en/tickets-portal
