Qevlar supports Single Sign-On via SAML 2.0. The integration requires a short back-and-forth between your team and Qevlar: you share a few values from your identity provider, we configure the connection on our end, then send you back the information you need to finalize the setup on your side.
Step 1 - Send your IdP details to Qevlar
From your identity provider's SAML configuration, collect the following and share them with your Qevlar contact, either your Technical Account Manager or Customer Success Manager:
-
x509 Signing Certificate - The Base64-encoded certificate used to sign SAML assertions from your IdP. ⚠️ We accept
.cer,.pem,.crt, and.certfiles. -
Sign-In URL - The SAML endpoint your IdP uses to authenticate users. In Entra ID this looks like
https://<your-idp-domain>/<saml-sso-endpoint - Sign-Out URL (optional) - The endpoint to redirect users to when they sign out of Qevlar. If not provided, users will simply be redirected to the Qevlar login page on sign-out.
Once Qevlar receives these values, we'll configure the connection and get back to you — typically within one business day.
Step 2 — Configure your IdP with Qevlar's values
After Qevlar has set up the connection on our end, we'll send you two values to enter into your IdP's SAML application:
| Parameter | Description |
|---|---|
| Entity ID | Identifies Qevlar as the service provider to your IdP. |
|
Reply URL (ACS URL) |
The URL your IdP should post SAML assertions to after authentication. |
Enter these values into your IdP's SAML application (typically under Basic SAML Configuration or equivalent) and save.
Configure attribute statements
Qevlar needs your IdP to include a few user attributes in the SAML assertion so we can identify and provision users correctly. In your IdP's SAML application (usually under Attribute Statements, Claims, or User Attributes), add the following:
| Attribute name | Value | Required |
|---|---|---|
email |
user.email | Yes — used as the unique identifier |
firstName |
user.firstName (or user.givenName) | Yes |
lastName |
user.lastName (or user.surname) | Yes |
After SSO is Enabled
Once both sides are configured, Qevlar will confirm that SSO is active for your organization. Your users will then be able to log in to platform.qevlar.com using their corporate credentials.