Ramp - SSO Configuration

Ramp - SSO Configuration

Alert
This application has not been formally tested by Kelvin Zero Inc. It is provided solely as a reference guide. If you encounter any issues, kindly submit a ticket directly through the support desk.
Quote
This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Ramp using Multi-Pass. SSO simplifies user authentication by allowing access to multiple applications with a single set of credentials. This integration enhances security and improves user experience across your organization.
Warning
To set up Multi-Pass with Ramp, ensure you meet the following requirements:
- Ramp admin rights
- MPAS Admin rights
- Make sure that all users intended to use SSO in Ramp are registered in your IdP and have the necessary permissions to access Ramp.
Important: Custom elements in URLs (like realm names) are case sensitive. Make sure to match the exact casing from your environment.





Ramp - SSO Configuration




Step 1 - Configure Ramp (Service Provider)

  • Log into Ramp as an Administrator.
  • Go to Settings > Company Settings.
  • Navigate to the Security tab.
  • Select Begin Setup under Identity Providers.
  • Select Custom Identity Provider.
  • You will be presented with a list of options and values. Rename it to Multi-Pass and insert the Metadata URL/File:
    https://ca.auth.kzero.com/realms/<TENANT_NAME>/protocol/saml/descriptor
  • Copy the Metadata URL for Ramp or download the Metadata XML file (needed in Step 2).
  • Under Enable Domains, select the company’s domain.
  • Click Exit and Test.
  • Upon successful test login, you will be directed to the Login methods tab with Multi-Pass displayed as a method for each user role.
  • Assign Multi-Pass to the necessary roles.
  • Select Save Changes.

Step 2 - Configure Multi-Pass (Identity Provider)

  • Open Multi-Pass Dashboard
  • Select the correct tenant and go to Integrations > Applications.
  • Select SAML in the custom integration section.

  • Browse to the Metadata URL obtained from Step 1 and save the XML file locally.
  • Select Upload File and upload the Ramp Metadata.

  1. Populate the SAML configuration fields as shown:
FieldValue
Client ID (=SP Entity ID)https://sso.ramp.com/__/auth/handler
Nameramp
DescriptionRamp SSO integration
Assertion Consumer Service URLhttps://sso.ramp.com/__/auth/handler
NameID Policy Formatemail


  • Click Add integration.
  • Click Advanced Console.

  • Go to Clients and search for Ramp.
  • Ensure all the fields are populated based on the tables below
General settings
FieldValue
Client IDhttps://sso.ramp.com/__/auth/handler
Nameramp
DescriptionRamp SSO integration
Always display in UION
Access settings
FieldValue
Home URL (IdP-initiated)https://ca.auth.kzero.com/<TENANT_NAME>/protocol/saml/clients/<APP_NAME>
Valid Redirect URIs (ACS)https://sso.ramp.com/__/auth/handler
IDP-Initiated SSO URL Name<APP_NAME>
SAML Capabilities
SettingValue
Name ID Formatemail
Force Name ID FormatON
Force POST BindingON
Include AuthnStatementON
Signature & Encryption
SettingValue
Sign DocumentsOFF
Sign AssertionsON
  • Navigate to the Keys tab and ensure both parameters are set to OFF.

    • Related Articles

    • D2L Brightspace - SSO Integration

      This application has not been formally tested by Kelvin Zero Inc. It is provided solely as a reference guide. If you encounter any issues, kindly submit a ticket directly through the support desk. This documentation provides a step-by-step guide to ...
    • Mulesoft - SSO Integration

      This application has been formally tested by Kelvin Zero Inc. This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Mulesoft using Multi-Pass. SSO simplifies user authentication by allowing access to multiple ...
    • SAML SSO Integration Guide

      This guide provides an overview of how to configure SAML Single Sign-On (SSO) between Multi-Pass and a third-party Service Provider (SP). Multi-Pass acts as the Identity Provider (IdP) in this federation model. Multi-Pass is working on SCIM support ...
    • Miro - SSO configuration

      This documentation has been tested and approved by Kelvin Zero's team This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Miro using MPAS. SSO simplifies user authentication by allowing access to multiple ...
    • Pipedrive – SSO configuration

      This application has been formally tested by Kelvin Zero Inc. This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Pipedrive using Multi-Pass. SSO simplifies user authentication by allowing access to multiple ...