Skip to main content

Note: Single Sign-On (SSO) is available as an add-on feature on the Enterprise plan only. See the Storyblok Pricing page for details.

Step 1: Find your Microsoft Entra Tenant ID

Follow Microsoft's documentation to find your Microsoft Entra Tenant ID.

Step 2: Contact Storyblok

Once you have your Tenant ID, contact your dedicated Storyblok representative and share:

If more than one domain will be used, that's supported — just list all domains you want enabled.

Example: domain1.com, domain2.com

Step 3: Create the enterprise application in Microsoft Entra ID

Log into Storyblok and follow Microsoft's guide to add an enterprise application for Storyblok.

Step 4: Configure the callback URLs

In Storyblok, go to Settings → SSO & Provisioning and copy your SSO Identifier.
(See the Organizations manual — security section for more.)

In Microsoft Entra ID, paste the following values — replacing YOUR-SSO-IDENTIFIER with your actual SSO Identifier:

Field name

Identifier (Entity ID)

Reply URL (Assertion Consumer Service URL)

Value

https://mapi.storyblok.com/saml/metadata?connection=YOUR-SSO-IDENTIFIER

https://mapi.storyblok.com/saml/consume?connection=YOUR-SSO-IDENTIFIER

China region: Replace https://mapi.storyblok.com with https://app.storyblokchina.cn in both URLs above.

Step 5: Verify the setup

Go to Storyblok and confirm the Sign in via SSO button appears for all users accessing any configured domain.