Skip to content
Log inBook a demo

Identity

Finly + SAML 2.0

Identity · Two-way sync · Live since 2024 · About 20 minutes to connect

What it does

Finly is a plain SAML 2.0 service provider, so any conforming identity provider connects by metadata exchange. This is the route for a directory nobody has written a named connector for — and it is the same code path every named one above uses.

What syncs

What moves, and which way.

Both directions, on every sync.Nothing here is a nightly batch —a record that changes at 14:02 is in the ledger before you look at it.

SAML 2.0 → Finly

  • Assertions from any conforming provider
  • Group or role attributes, mapped to Finly roles
  • Attribute statements, as entity and cost centre
  • Single logout, where the provider sends it
  • Signed metadata, refreshed on rotation
  • Assurance level, where the provider asserts it

Finly → SAML 2.0

  • Sign-in and session events, back to the log
  • Role changes made inside Finly
  • SCIM 2.0 provisioning, where the provider supports it

Connected

What it looks like once it is on.

The Finly ledger view for a connected payments account: €1.84M settled this month, €41,900 of processing fees at 2.3% of gross, no unreconciled payouts, a twelve-week payout chart split between cards, gross and reimbursements, and three lines needing a human.

One login, one leaver process.

Everyone signs in through SAML 2.0 and lands on the role their group says they should have.Deprovision there and the Finly session ends the same minute, with the cards frozen behind it.

Before you start

What you need, and what it will not do.

You need a SAML 2.0 tenant with rights to add an application, and a Finly plan on Scale or above —SSO is not on Core.Finly is a SAML 2.0 service provider with SCIM 2.0 for provisioning, so setup is the metadata exchange you have done before:upload ours, paste yours, map three attributes, test with one user.

Two things it deliberately will not do.It will not lock you out —break-glass password access stays on for the owner account until you switch it off yourself, and it can be restored from the recovery flow.And it will not grant spend:SAML 2.0 decides who gets in and which role they land on, while card limits and approval rights stay in Finly, where finance owns them.

Okta

SAML sign-in with SCIM provisioning.

OneLogin

One directory, one set of card rights.

Get started

Stop closing the month in arrears.

Book a 30-minute demo and we'll run your own last month through a sandbox, so you can see the close before you commit to anything.