Note: Single Sign-On (SSO) is available as an add-on feature on the Enterprise plan only. See the Storyblok Pricing page for details.
Step 1: Find your Microsoft Entra Tenant ID
Follow Microsoft's documentation to find your Microsoft Entra Tenant ID.
Step 2: Contact Storyblok
Once you have your Tenant ID, contact your dedicated Storyblok representative and share:
- Your Tenant ID
- The domain(s) you want to use for SSO login
If more than one domain will be used, that's supported — just list all domains you want enabled.
Example: domain1.com, domain2.com
Step 3: Create the enterprise application in Microsoft Entra ID
Log into Storyblok and follow Microsoft's guide to add an enterprise application for Storyblok.
Step 4: Configure the callback URLs
In Storyblok, go to Settings → SSO & Provisioning and copy your SSO Identifier.
(See the Organizations manual — security section for more.)
In Microsoft Entra ID, paste the following values — replacing YOUR-SSO-IDENTIFIER with your actual SSO Identifier:
Field name
Identifier (Entity ID)
Reply URL (Assertion Consumer Service URL)
Value
https://mapi.storyblok.com/saml/metadata?connection=YOUR-SSO-IDENTIFIER
https://mapi.storyblok.com/saml/consume?connection=YOUR-SSO-IDENTIFIER
China region: Replace https://mapi.storyblok.com with https://app.storyblokchina.cn in both URLs above.
Step 5: Verify the setup
Go to Storyblok and confirm the Sign in via SSO button appears for all users accessing any configured domain.