Log inGet Vautir

Search the help center, features, guides and more.

Single sign-on

Sign in to Vautir through your company's identity provider, and for admins, set up single sign-on with OpenID Connect or SAML 2.0.

With single sign-on, a new device gets into an organization’s account only after the company’s identity provider has vouched for the person: Okta, Microsoft Entra ID, Google Workspace, or any provider that speaks OpenID Connect or SAML 2.0. The provider says who you are, and never holds a key.

Signing in

  1. Log in as always, with your master password and Secret Key.
  2. The app opens your company’s sign-in page in the browser, and shows a six-digit code.
  3. Sign in at your provider.
  4. A page asks Allow this login?, with your address and six digits. If they match the code in the app, choose Allow.

If a page asks you to allow a login you didn’t start, refuse it: nobody but you should have an app showing that code.

A device that’s already signed in stays so until its session ends, and unlocking it works offline. The web vault asks at every login.

Setting it up, for admins

In the console, open Policies, Single sign-on. Your Vautir account’s address must be the address your provider knows each person by.

OpenID Connect

  1. At your provider, make a web application for Vautir with the redirect URI the console shows, the authorization code flow, and the scopes openid email profile.
  2. Give the console the provider’s issuer, the client ID and the client secret, and choose Turn on.

SAML 2.0

  1. At your provider, make a SAML application with the ACS URL and the entity ID the console shows. Have it sign the assertion with SHA-256, and send the person’s email address as the NameID.
  2. Give the console the provider’s entity ID, Vautir’s entity ID as you gave it there, the provider’s single sign-on URL and its signing certificate, and choose Turn on.

An address with no provider behind it, or something that isn’t a certificate, turns nothing on.

What to know

  • Owners sign in without it, so a provider that’s down or set up wrong never locks a company out. Admins who aren’t owners are asked like everyone else.
  • Deactivating someone at the provider stops them getting a new session. To take the organization’s vaults from them at once, use SCIM, or remove them.
  • Everyone keeps a master password, unless the company runs a key connector.
  • One provider for each organization, and no single logout.
  • Single sign-on is part of Teams and Business.

Last updated October 4, 2026