Intercom - SSO configuration
Valid redirect URIs

Please note that this application has not been formally tested by Kelvin Zero Inc. It is provided solely as a reference guide. If you encounter any issues, kindly submit a ticket directly through the support desk.
This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Intercom using MPAS. SSO simplifies user authentication by allowing access to multiple applications with a single set of credentials. This integration enhances security and improves user experience across your organization
To set up Multi-Pass with Intercom, ensure you meet the following requirements:
- Intercom admin rights
- MPAS Admin rights
- Make sure that all users intended to use SSO in Intercom are registered in your IdP and have the necessary permissions to access Intercom.
Important: Custom elements in URLs (like realm names) are case sensitive. Make sure to match the exact casing from your environment.
Intercom - SSO configuration
Access the Dashboard
- Open Multi-Pass Dashboard
- Select your tenant
- In the left-hand menu, click Integrations, then select Applications
- Under Custom Integration, click SAML
Field | Value |
---|
SP Entity ID / Audience / Client ID | https://app.intercom.com/saml/<SAML Name> |
ACS / Assertion Consumer Service URL | https://app.intercom.com/saml/<SAML Name>/consume |
NameID Policy Format | Email |
Name | intercom |
Description | SSO integration for Intercom |
- At the bottom of the form, download the X.509 certificate, it will be needed in Intercom.
- Click Add Integration to create the app.
Adjust Advanced Settings in MPAS Console
- On the left side, click on advanced console
- Click on Client
- Search for the client you just created, and make sure that all the fields are correctly completed
- General Settings
- Access Settings
- SAML Capabilities
Setting | Value |
---|
Name ID format | email |
Force Name ID format | OFF |
Force POST binding | ON |
Include AuthnStatement | ON |
- Signature & Encryption
Setting | Value |
---|
Sign documents | OFF |
Sign assertions | ON |
Enable SAML SSO in Intercom
- Sign in to your Intercom workspace
- Go to Settings → Workspace → Security
- Choose Require SAML SSO as authentication method
- Note the SAML Name (grayed-out field)
Complete the SAML Configuration
- Click Save. Verify domain ownership if required via DNS TXT record.
Enforce and Test SSO
- Activate Require SAML SSO in Intercom
- Visit the Intercom login page and enter your email
- It should redirect to the MPAS login page
- Upon successful login, access Intercom
Related Articles
Wrike - SSO configuration
This documentation has been tested and approved by Kelvin Zero's team This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Wrike using MPAS. SSO simplifies user authentication by allowing access to multiple ...
Lusha - SSO configuration
Please note that this application has not been formally tested by Kelvin Zero Inc. It is provided solely as a reference guide. If you encounter any issues, kindly submit a ticket directly through the support desk. This documentation provides a ...
Huntress - SSO configuration
This documentation has been tested and approved by Kelvin Zero's team This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Huntress using MPAS. SSO simplifies user authentication by allowing access to multiple ...
FortiClient / FortiGate - SSO Configuration
Please note that this application has not been formally tested by Kelvin Zero Inc. It is provided solely as a reference guide. If you encounter any issues, kindly submit a ticket directly through the support desk. This documentation provides a ...
Rocket.chat - SSO configuration
This documentation has been tested and approved by Kelvin Zero's team This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Rocket.chat using MPAS. SSO simplifies user authentication by allowing access to multiple ...