Skip to main content
If your organisation already has SSO configured, an administrator can use the guided update journey on the Security & Data page instead of the SSO settings form. This is for organisations already on SSO. If you are setting up SSO for the first time, see Single Sign-On (SSO) Setup instead. Mention Me needs a new application in your identity provider. Your existing app is tied to old callback URLs and cannot be reused, even if the provider is the same.
Do not reuse your existing Mention Me application, client ID, or secret. Create a new one using the instructions below.

Create the Connection

On Security & Data, follow the on-screen step to create the new connection. Mention Me gives you an ACS URL and an Entity ID to use below.

Okta Setup

1

Open the Okta Admin portal

Go to Applications, then Create App Integration.
2

Choose SAML 2.0

Select SAML 2.0 as the sign-in method.
3

Set the ACS URL

Paste the ACS URL from Mention Me into Single sign-on URL.
4

Set the entity ID

Paste the entity ID from Mention Me into Audience URI (SP Entity ID).
5

Add attribute statements

Add: mail = user.profile.email, firstName = user.profile.firstName, lastName = user.profile.lastName.
6

Assign the app

On the Assignments tab, assign the app to yourself and anyone else who will test sign-in.
7

Download the IdP metadata

On the Sign On tab, download the Identity Provider metadata file.

Mention Me Setup

Upload the metadata file on Security & Data. Once it is saved, you can test the connection (see Testing Your New Connection below).

Testing Your New Connection

Once your provider details are saved, copy the test link from Security & Data and open it to sign in with a few accounts using the new connection. This signs in to Mention Me. Mention Me Classic keeps using your previous SSO app throughout, so testing carries no risk to your current logins.
This finishes in Mention Me. After a successful sign-in, an administrator sees a prompt on Mention Me with Keep testing or Switch Classic to the new connection. Signing in on its own does not switch anything - only confirming that prompt makes Mention Me Classic use the new connection too.
If your provider requires users or groups to be assigned to an application before they can sign in (for example Okta), assign the new application to everyone who needs access, not just the accounts used for testing, before confirming the switch. Anyone left unassigned will be unable to sign in once Classic moves over. Providers without this step (for example Google, which uses its own User access controls, or Auth0 and other generic OIDC providers) should check access is correct in their own provider instead.

Rolling Back

There is no self-serve rollback. If you need to revert to your previous SSO connection after confirming the switch, contact support.
Last modified on September 16, 2026