Enabling front-end SSO for Gradual allows community members to sign in to Gradual using their existing credentials from another platform. This creates a seamless login experience while linking their Gradual profile to an existing community account. Once authenticated, members can access content, register for events, participate in forums, and take advantage of other community features without needing to manage a separate login.
Setting up front-end SSO
Prerequisites
Each community needs to have and/or share the following before we can move forward with front-end community SSO implementation:
Sandbox and Production Gradual tenants
Identity Provider (Okta, Onelogin, Auth0)
Preferred Protocol (We support OAuth 2.0 with OpenID Connect / OIDC or SAML 2.0)
Expected Timeline for SSO Deployment
What Gradual Shares
Once we know what protocol you are using, Gradual provides these values for each instance (sandbox and production). These are needed to create the SAML app / OAuth client in your IdP.
OAuth 2.0 / OpenID Connect (OIDC) | SAML 2.0 |
Redirect / Callback URL: | ACS / Reply URL (HTTP-POST): https://dashboard.gradual.com/<your-slug>/callback/saml |
What Gradual Needs
OAuth 2.0 / OpenID Connect (OIDC) | SAML 2.0 |
The easiest option is to share your OpenID Discovery Document URL (https://[your-provider.com]/…/.well-known/openid-configuration) If the discovery document is not available, please provide:
Is the token-endpoint authorized via request body or Authorization header? | The easiest option is to share your IdP metadata XML file. Alternatively, please provide the following:
Does the X.509 certificate expire? If yes, then what’s the rotation schedule? |
Claims/Attributes Mapping
Gradual needs to know how to map member profile fields from the SSO payload to Gradual. For community-side logins, we recommend scheduling a meeting with our team to discuss how user profile information should be mapped to Gradual. There can be different arrangements regarding the fields like names, headlines, profile pictures, etc.
Tell us which claim (OIDC) or attribute (SAML) carries each field, including:
Email (always required)
First name and last name; or
Full name which we could use to parse into first/last names (less ideal as parsing could be inaccurate)
Picture URL
Company/organization
Position/job title
For profile fields that are required in Gradual but not provided in SSO payload (like company and title, very often), we can set default values for them upon user sign-up. It is also possible to map SSO user profile attributes to custom Gradual profile questions.
Please let us know whether we can trust all of your user’s email as already verified (if not, we will require a separate email verification step for all new sign-ons)
Testing on a Sandbox Instance
Gradual can provision a sandbox instance of your community which you may use to test your SSO integration. We configure SSO on the sandbox instance first and verify the end-to-end login with you (using test accounts you provide or create). Once you sign off, we replicate the configuration on the production instance and go live.
Each instance has its own domain — and therefore its own Callback URL (and SP Entity ID for SAML protocol) — so register both sets in your IdP.
LOCKOUT RISK: Because front-end SSO replaces email/password login, a misconfiguration can lock members out of the community. Always validate on the sandbox first.
Go Live on Production
At cutover, Gradual switches your production dashboard to SSO and verifies the configuration. It's best to determine a date/time for the switch with the Gradual team to ensure both sides are online and ready for testing. We recommend an immediate smoke test with one real admin account. If admins can't get in, Gradual can revert the dashboard to email/password login while we correct the configuration — so keep at least one Gradual-side admin contact available during cutover.
Logging In with SSO on the front end community
When you use SSO login to access the frontend, you will be redirected to the designated IDP. Once the user is logged in and authenticated, they will be redirected to the Gradual community bypassing the login step.

