


- From your HubSpot dashboard, click the gear icon in the top right corner.
• Click “Security.”
• Locate the line “Get single sign-on (SSO) for your account” and click “Manage.”• A new window will open on the right—this is where you need to enter information from MPAS.Copy the Audience URI (Service provider Entity ID) and Sign on URL, ACS, Recipient or Redirect you will need it
- Open Multi-Pass Dashboard
- Select your deployment, and click on advanced console
- Go to “Client”, and click “Create.”
- Fill in the required fields.
Client type : SAMLClient ID : Audience URI (Service provider Entity ID) from HubspotName : HubSpotDescription :Always display UI : ON
- Click “Next” and complete the following fields with the information provided below.
Identity Provider issuer URL:https://ca.auth.kzero.com/realms/<REALM>

• In MPAS, go to the left column and click “Realm Settings” to access the RS256 information required for the X.509 certificate.Copy the certificate, and do not forget to add -----BEGIN CERTIFICATE----- and -----END CERTIFICATE----- (Without space before the first character and the last one)
• Go back to HubSpot and complete the required fields.