Intercom - SSO configuration
Valid redirect URIs

Please note that this application has not been formally tested by Kelvin Zero Inc. It is provided solely as a reference guide. If you encounter any issues, kindly submit a ticket directly through the support desk.
This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Intercom using MPAS. SSO simplifies user authentication by allowing access to multiple applications with a single set of credentials. This integration enhances security and improves user experience across your organization
To set up Multi-Pass with Intercom, ensure you meet the following requirements:
- Intercom admin rights
- MPAS Admin rights
- Make sure that all users intended to use SSO in Intercom are registered in your IdP and have the necessary permissions to access Intercom.
Important: Custom elements in URLs (like realm names) are case sensitive. Make sure to match the exact casing from your environment.
Intercom - SSO configuration
Access the Dashboard
- Open Multi-Pass Dashboard
- Select your tenant
- In the left-hand menu, click Integrations, then select Applications
- Under Custom Integration, click SAML
| Field | Value |
|---|
| SP Entity ID / Audience / Client ID | https://app.intercom.com/saml/<SAML Name> |
| ACS / Assertion Consumer Service URL | https://app.intercom.com/saml/<SAML Name>/consume |
| NameID Policy Format | Email |
| Name | intercom |
| Description | SSO integration for Intercom |
- At the bottom of the form, download the X.509 certificate, it will be needed in Intercom.
- Click Add Integration to create the app.
Adjust Advanced Settings in MPAS Console
- On the left side, click on advanced console
- Click on Client
- Search for the client you just created, and make sure that all the fields are correctly completed
- General Settings
- Access Settings
- SAML Capabilities
| Setting | Value |
|---|
| Name ID format | email |
| Force Name ID format | OFF |
| Force POST binding | ON |
| Include AuthnStatement | ON |
- Signature & Encryption
| Setting | Value |
|---|
| Sign documents | OFF |
| Sign assertions | ON |
Enable SAML SSO in Intercom
- Sign in to your Intercom workspace
- Go to Settings → Workspace → Security
- Choose Require SAML SSO as authentication method
- Note the SAML Name (grayed-out field)
Complete the SAML Configuration
- Click Save. Verify domain ownership if required via DNS TXT record.
Enforce and Test SSO
- Activate Require SAML SSO in Intercom
- Visit the Intercom login page and enter your email
- It should redirect to the MPAS login page
- Upon successful login, access Intercom
Related Articles
Huntress - SSO configuration
This documentation has been tested and approved by Kelvin Zero's team This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Huntress using MPAS. SSO simplifies user authentication by allowing access to multiple ...
Lusha - SSO configuration
Please note that this application has not been formally tested by Kelvin Zero Inc. It is provided solely as a reference guide. If you encounter any issues, kindly submit a ticket directly through the support desk. This documentation provides a ...
FortiClient / FortiGate - SSO Configuration
Please note that this application has not been formally tested by Kelvin Zero Inc. It is provided solely as a reference guide. If you encounter any issues, kindly submit a ticket directly through the support desk. This documentation provides a ...
SAML SSO Integration Guide
This guide provides an overview of how to configure SAML Single Sign-On (SSO) between Multi-Pass and a third-party Service Provider (SP). Multi-Pass acts as the Identity Provider (IdP) in this federation model. Multi-Pass is working on SCIM support ...
Rocket.chat - SSO configuration
This documentation has been tested and approved by Kelvin Zero's team This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Rocket.chat using MPAS. SSO simplifies user authentication by allowing access to multiple ...