Intercom - SSO configuration

Intercom - SSO configuration

Valid redirect URIs Alert
Please note that this application has not been formally tested by Kelvin Zero Inc. It is provided solely as a reference guide. If you encounter any issues, kindly submit a ticket directly through the support desk.
Quote
This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Intercom using MPAS. SSO simplifies user authentication by allowing access to multiple applications with a single set of credentials. This integration enhances security and improves user experience across your organization
Warning
To set up Multi-Pass with  Intercom, ensure you meet the following requirements:
-  Intercom admin rights
- MPAS Admin rights
- Make sure that all users intended to use SSO in Intercom are registered in your IdP and have the necessary permissions to access Intercom.
Important: Custom elements in URLs (like realm names) are case sensitive. Make sure to match the exact casing from your environment.




Intercom - SSO configuration




Step 1 - Configure Multi‑Pass (MPAS) as Identity Provider

Access the Dashboard

  1. Open Multi-Pass Dashboard

  1. Select your tenant
  2. In the left-hand menu, click Integrations, then select Applications
  3. Under Custom Integration, click SAML


Fill the SAML Integration Form Using Intercom Information

FieldValue
SP Entity ID / Audience / Client IDhttps://app.intercom.com/saml/<SAML Name>
ACS / Assertion Consumer Service URLhttps://app.intercom.com/saml/<SAML Name>/consume
NameID Policy FormatEmail
Nameintercom
DescriptionSSO integration for Intercom
  1. At the bottom of the form, download the X.509 certificate, it will be needed in Intercom.

  1. Click Add Integration to create the app.

Adjust Advanced Settings in MPAS Console

  1. On the left side, click on advanced console

  1. Click on Client
  2. Search for the client you just created, and make sure that all the fields are correctly completed

  1. General Settings
SettingValue
Client IDhttps://app.intercom.com/saml/<SAML Name>
Nameintercom
DescriptionSSO integration
Always display in UION

  1. Access Settings
SettingValue
Home URLhttps://ca.auth.kzero.com/realms/<TENANT_NAME>/protocol/saml/clients/<APP_NAME>
Valid Redirect URIshttps://app.intercom.com/saml/<SAML Name>/consume
IDP-Initiated SSO URL name<APP_NAME>

  1. SAML Capabilities
SettingValue
Name ID formatemail
Force Name ID formatOFF
Force POST bindingON
Include AuthnStatementON

  1. Signature & Encryption
SettingValue
Sign documentsOFF
Sign assertionsON


Step 2 - Configure Intercom as Service Provider

Enable SAML SSO in Intercom

  1. Sign in to your Intercom workspace
  2. Go to Settings → Workspace → Security
  3. Choose Require SAML SSO as authentication method
  4. Note the SAML Name (grayed-out field)

Complete the SAML Configuration

FieldValue
Single Sign‑On URLhttps://ca.auth.kzero.com/realms/<TENANT_NAME>/protocol/saml
X.509 CertificatePaste PEM-formatted cert from MPAS
Allowed Domainsexample.com, mycompany.org
  1. Click Save. Verify domain ownership if required via DNS TXT record.

Enforce and Test SSO

  • Activate Require SAML SSO in Intercom
  • Visit the Intercom login page and enter your email
  • It should redirect to the MPAS login page
  • Upon successful login, access Intercom

    • Related Articles

    • Wrike - SSO configuration

      This documentation has been tested and approved by Kelvin Zero's team This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Wrike using MPAS. SSO simplifies user authentication by allowing access to multiple ...
    • Lusha - SSO configuration

      Please note that this application has not been formally tested by Kelvin Zero Inc. It is provided solely as a reference guide. If you encounter any issues, kindly submit a ticket directly through the support desk. This documentation provides a ...
    • Huntress - SSO configuration

      This documentation has been tested and approved by Kelvin Zero's team This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Huntress using MPAS. SSO simplifies user authentication by allowing access to multiple ...
    • FortiClient / FortiGate - SSO Configuration

      Please note that this application has not been formally tested by Kelvin Zero Inc. It is provided solely as a reference guide. If you encounter any issues, kindly submit a ticket directly through the support desk. This documentation provides a ...
    • Rocket.chat - SSO configuration

      This documentation has been tested and approved by Kelvin Zero's team This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Rocket.chat using MPAS. SSO simplifies user authentication by allowing access to multiple ...