Single Sign-On, SSO, lets your team sign in to Ordergroove using your company’s existing identity provider instead of a separate Ordergroove username and password. Your IT team controls who has access, access goes away when someone leaves, and your own security rules, including multi-factor authentication, apply to Ordergroove the same way they apply to everything else.
Ordergroove supports four SSO paths: Microsoft Entra ID, Okta, Ping, and Shopify.
This guide covers how each one works, what you need before you start, how users and permissions are handled, and what to do when a sign-in doesn’t go through. If you’re reviewing Ordergroove as part of a security assessment, take a look at Supported protocols and security details.
How SSO works at Ordergroove
Three of the four paths - Microsoft Entra ID, Okta, and Ping - connect Ordergroove to your company’s identity provider (IdP). The fourth, Shopify SSO, works differently: it uses your Shopify staff account, with no separate identity provider involved.
| Path | Who it’s for | Needs My Organization | Where you sign in |
|---|---|---|---|
| Microsoft Entra ID | Merchants using Entra, formerly Azure AD | Yes | Ordergroove Admin login page |
| Okta | Merchants using Okta | Yes | Ordergroove Admin login page |
| Ping | Merchants using PingIdentity | Yes | Ordergroove Admin login page |
| Shopify | Merchants on Shopify | No | Shopify admin, under Apps |
The three identity provider paths work the same way. You tell Ordergroove which IdP to trust, your IdP administrator authorizes Ordergroove, and your team signs in at the Ordergroove Admin login page by clicking their provider’s tile. Users have to be invited to Ordergroove before they can sign in.
Shopify SSO is already in place for merchants on Shopify. There’s nothing to configure and no identity provider to connect. Anyone with a Shopify staff account that has permission to view apps can open Ordergroove from the Shopify admin, and access is managed entirely in Shopify.
Because Shopify SSO doesn’t use My Organization, most of the setup, invitation, and permission steps below apply only to the Entra, Okta, and Ping paths. Where Shopify behaves differently, it’s called out.
Requirements
Before you get started, you must have:
- An existing Ordergroove merchant account. If you don’t have one yet, please contact support for assistance.
- Admin access to your identity provider. Someone on your side needs to be able to authorize a new application in Entra, Okta, or Ping.
- My Organization enabled on your account. SSO runs on top of My Organization, which is how users are invited and mapped to your stores.
Feature Access: My Organization is currently in Early Access. Because SSO depends on it, turning on SSO means enrolling in My Organization as well. Reach out to your CSM to get started.
Shopify merchants don’t need any of the above. Shopify SSO is already enabled on your Ordergroove account and uses your existing Shopify staff permissions.
Setting up SSO
Setup differs by provider, and each has its own guide with the full steps. Here’s what’s involved.
Microsoft Entra ID
Ordergroove is listed in the Microsoft Entra application gallery, so there’s no app registration for you to build. There are two steps:
- Send your Entra Tenant ID to Ordergroove Support. We’ll confirm once your account is set up with it.
- Authorize the Ordergroove application to authenticate against your Entra IdP. Entra SSO has the Application ID you’ll need.
You don’t need to create a dedicated security group for Ordergroove.
Okta
- In Okta, go to Applications → Browse App Catalog and add Ordergroove.
- Assign the users or groups who should be able to sign in.
- Open the Ordergroove app’s Sign On tab and make note of the Client ID and Client Secret.
- Contact Ordergroove Support with your Okta domain, Client ID, Client Secret, and the name of the merchant account you want to connect.
Ordergroove supports one Okta application per Okta domain. If you need more than one merchant account authenticating through the same Okta tenant, talk to support before you start. For more information, take a look at Okta.
Ping
Ordergroove sets up the Ping integration for you. Reach out to your CSM or Ordergroove Support to begin and we’ll let you know what we need from your side. For more information, take a look at Ping Single Sign-On.
Shopify
There’s nothing to set up. Shopify SSO is enabled on your Ordergroove account, and access follows your Shopify staff permissions. Make sure anyone who needs Ordergroove has permission to view apps in your Shopify admin.
Logging in
Where you sign in depends on your path.
Entra, Okta, and Ping
Go to the Ordergroove Admin login page and click your provider’s tile:
- Entra — Select Sign in to an Organization under Sign-in options.
-
Okta — Enter your Okta domain. It looks like
acme.okta.com. - Ping — Enter your Ping organization.
Production is https://rc3.ordergroove.com and staging is https://rc3.stg.ordergroove.com. If you already have an active session with your identity provider, you usually won’t be asked for credentials at all.
Shopify
Sign in to your Shopify admin, then go to Apps → Ordergroove Subscriptions. You’ll be taken straight into Ordergroove.
We recommend starting from the Shopify admin rather than the Log in with Shopify button on the Ordergroove login page. The button works, but it depends on a browser session that isn’t always in place, and it’s the source of most Shopify sign-in problems.
Note: SSO is configured separately for each environment. Access in production doesn’t carry over to staging, and each environment needs its own invitation.
Managing users and permissions
Users have to be invited before they can sign in
Ordergroove doesn’t create accounts automatically when someone authenticates. A user has to be invited, and has to accept that invitation, before SSO will let them in. Signing in with a valid company account that was never invited returns an error.
Invitations are sent from My Organization. When you invite someone, you choose which stores they can reach and whether they get admin rights.
Admin rights and user permissions are different things
- Admin rights control user management: inviting people, removing them, and changing which stores they can see.
- User permissions control what someone can do inside Ordergroove — view analytics, create API keys, work in the Customers page, and so on.
Admins can’t change user permissions themselves. To adjust what a user can do, submit a support ticket. This is the same whether or not you’re on My Organization, and you can send one ticket covering several users at once.
New users receive your organization’s default permissions. If no defaults are set, they can land in Ordergroove with very little access, so it’s worth setting them before you invite a group. For more information, take a look at User Permissions.
The Users page after SSO
Once SSO is turned on, the Users page is hidden. This is intentional — it stops new username and password accounts being created alongside SSO. Manage your users in My Organization instead.
If you run periodic access reviews, contact support for a current list of users and their permissions.
Shopify
All user management happens in Shopify. Add or remove staff, and set app permissions, in your Shopify admin. There’s no Users page or invitation flow in Ordergroove for these stores.
Supported protocols and security details
This section covers the questions that usually come up during a security or IT review.
- Protocol. Ordergroove supports OIDC. SAML is not supported. If your review asks for SAML metadata, an XML file, or an Entity ID, those don’t apply — contact support and we’ll provide OIDC configuration details instead.
-
User attributes shared. Ordergroove requests three claims:
given_name,family_name, andemail. Nothing else. - Multi-tenant application. For Entra, Ordergroove runs its own multi-tenant application that authenticates against your tenant. You don’t register an application in your own tenant, and you don’t supply an Application ID to us.
- Multiple tenants and providers. Ordergroove can be configured with more than one tenant, and with more than one identity provider, at the same time.
-
Tenant migrations. Entra users are matched on the
oidandtidclaims rather than on email address, so changing user principal names or email domains generally doesn’t break existing access. Inviting brand-new users mid-migration is the exception. Send us your new Tenant ID at least two weeks ahead and we can test the flow with you first. - Multi-factor authentication. Ordergroove doesn’t enforce MFA itself. Enforce it at your identity provider and it applies to Ordergroove along with your other applications. For most merchants this is the main reason to move to SSO.
- Automatic provisioning. SCIM and just-in-time provisioning aren’t supported. Users are invited manually, and you remove access by removing them in My Organization or asking support to deactivate them.
- Other identity providers. Entra, Okta, and Ping are the supported identity providers today. Others, including JumpCloud, aren’t supported. If you use a different provider, talk to your CSM — adding one is possible, but it’s a scoped piece of engineering work rather than a configuration change.
- Your shoppers. SSO covers your team’s access to the Ordergroove Admin. It doesn’t apply to the Subscription Manager, where your customers manage their own subscriptions after signing in to your storefront.
Troubleshooting
“Your account has not been fully set up. Please contact support for assistance.”
The invitation hasn’t been accepted yet. Open the invitation email, click the link, and finish creating the account before using the SSO tile. This is by far the most common SSO error.
You authenticate successfully but land back on the login page.
Usually a stale session. Sign out of Ordergroove everywhere, clear your cache and cookies, and try again in a single window — or use an incognito window for a fresh connection.
Shopify SSO doesn’t work in Safari.
Safari’s Prevent cross-site tracking setting blocks the connection between Shopify and Ordergroove. Turn it off, or use Chrome instead. Take a look at How to disable Safari security settings.
“The username or password you entered does not match our records” after signing in with your provider.
The invitation probably went to a different address than the one your identity provider sends us. Agency and contractor addresses are a common cause. Check the address on the invitation against the one you actually authenticate with.
Okta returns an error before you reach Ordergroove.
Your Okta administrator may not have assigned you to the Ordergroove application. Check the assignment in Okta first.
You get in, but the navigation is nearly empty or you only see one section.
This is a permissions issue rather than a sign-in issue. Sign out and back in first, since permission changes only take effect on a new session. If it persists, submit a support ticket.
You used to sign in with a username and password, and now SSO won’t work.
An existing account under the same email address can block SSO sign-in. Ordergroove doesn’t migrate accounts automatically — reach out to support and we’ll convert it.
A Shopify user can’t find Ordergroove in the Shopify admin.
Check their Shopify staff permissions for app access. If they’re a collaborator rather than staff, confirm the collaborator account has the same permissions.
Nothing works, on any browser or device.
Check the clock on the machine. Sign-in tokens are time-sensitive, and a device clock that’s meaningfully wrong will fail authentication every time.
Common questions
Do we have to use My Organization to use SSO?
Yes, for Entra, Okta, and Ping. My Organization is how users are invited and mapped to stores, and SSO is built on top of it. Shopify SSO is the exception and doesn’t require it.
Can we use SAML?
No. Ordergroove supports OIDC only.
Does Ordergroove support multi-factor authentication?
Not on its own. Enforce MFA at your identity provider and it applies when your team signs in to Ordergroove.
Can users be provisioned automatically from our directory?
No. SCIM and just-in-time provisioning aren’t supported, so each user needs an invitation before they can sign in.
Can we connect more than one identity provider, or more than one tenant?
Yes. Ordergroove can be configured with multiple tenants and multiple providers at the same time.
What happens to our existing username and password accounts?
They stay active until they’re deactivated. Most merchants invite everyone to SSO first, then ask support to deactivate the remaining password accounts once the team has moved over. Existing accounts aren’t migrated automatically — contact support if you need one converted.
Does SSO apply to staging as well as production?
Each environment is configured separately and needs its own invitations. You can have SSO in one and not the other.
Can our admins change what a user is allowed to do?
Not directly. Admins control who is invited and which stores they can reach; permission changes go through a support ticket.
We use a different identity provider. Can you support it?
Not today. Entra, Okta, and Ping are the supported providers. Let your CSM know which one you use — adding a provider is possible, but it’s engineering work that has to be scoped and prioritized.
Additional information
If you have any questions, or you’re working through a security review and need something we haven’t covered here, please reach out to support and we’ll be happy to help.