Single Sign-On FAQ

Pipeline's SSO is a signed-link API of our own design, issued as a secret key to a master admin. Answers to the common questions about standards support, keys, cost, and what happens to normal password logins.

Does Paperless Pipeline support SAML or Okta-style SSO?

No. Pipeline's SSO is a proprietary signed-link API using HMAC-SHA256. There's no SAML metadata to exchange and no identity-provider application to install — if your IT team is planning around an identity provider, this isn't the same thing.

Does it support OAuth 2.0?

No. OAuth 2.0 isn't supported either.

Can our platform control or end a Pipeline session?

No. Pipeline's SSO signs a person in; it doesn't hand session control back to your system.

Who can request SSO for our account?

Any master admin. Every master admin on an account can authorize an SSO key request, and the authorization has to come to us in writing.

Is there a charge for the SSO keys?

No. The development key and the production key are both free.

Why are there two keys?

So the integration is proven before it touches live accounts. The development key works against dev.paperlesspipeline.com; the production key is issued once you tell us the development test succeeded.

Will you build the integration for us?

No — we supply the pieces, your developer writes the code. You get documentation, the keys, and a test user with a real Pipeline User ID to build against.

Can people still log in with a password once SSO is on?

Yes. Turning SSO on doesn't close the normal login page.

We have more than one Pipeline account. Do we need a key for each?

It depends how the accounts are related. Accounts linked under an Enterprise share the same production key, and accounts added later are enabled automatically. A separate, unlinked account has needed its own. Ask us which applies to your setup before you build against a key.

Does turning on the Enterprise Portal disrupt our existing SSO?

No. Setting up an Enterprise leaves an existing SSO configuration alone.

Can we pull transaction data or documents through the SSO API?

No — it authenticates people, it doesn't move data. For transaction data flowing out of Pipeline, the Zapier integration is the path; for documents, use your monthly backups.

If Pipeline has an outage, does SSO keep working?

No. SSO runs on Pipeline's servers, so there's no independent failover — during an outage, SSO logins fail the same way direct logins do. Check status.paperlesspipeline.com.

Learn More

Sign your people into Pipeline straight from your own portal, with no second password to type. What Pipeline offers is a signed-link API we built ourselves — not SAML, and not OAuth.

See Single Sign-On

Still Have Questions?

Didn't find your answer above? Email us at help@paperlesspipeline.com and we'll help.