MarketScale uses WorkOS to power its SSO integration, which means you can connect virtually any identity provider that supports SAML 2.0 or OpenID Connect (OIDC). Below is a list of providers that have been tested and are fully supported, along with protocol and directory sync compatibility details.
Fully Supported Providers
The following identity providers have been verified to work with MarketScale SSO. If your provider is on this list, you can proceed with setup confidently.
Provider | Protocols Supported | Notes |
Microsoft Entra ID (Azure AD) | SAML 2.0, OIDC | Most common provider among MarketScale customers. Supports automatic user provisioning via SCIM. |
Okta | SAML 2.0, OIDC | Supports directory sync for automatic user provisioning. |
Google Workspace | SAML 2.0 | Supports SSO. Directory sync available separately. |
OneLogin | SAML 2.0, OIDC | Full SSO and directory sync support. |
PingFederate / PingOne | SAML 2.0, OIDC | Enterprise-grade provider with full support. |
JumpCloud | SAML 2.0 | SSO and directory sync supported. |
CyberArk | SAML 2.0 | SSO supported. |
Other SAML 2.0 or OIDC Providers
If your identity provider supports SAML 2.0 or OIDC but is not listed above, it will likely work with MarketScale. During the setup portal configuration, you can select "Other SAML" or "Other OIDC" and enter your provider's metadata manually. You will need:
For SAML 2.0: Your IdP's SSO URL, Entity ID, and x.509 signing certificate.
For OIDC: Your IdP's Client ID, Client Secret, and Discovery URL.
What Protocol Should I Choose?
If your identity provider supports both SAML 2.0 and OIDC, either will work. SAML 2.0 is the more established standard and is what most enterprise IT teams are familiar with. OIDC is newer and can be simpler to configure. Choose whichever your team is more comfortable with.
Directory Sync (SCIM) Compatibility
Directory sync uses the SCIM protocol to automatically create, update, and deactivate user accounts in MarketScale based on changes in your identity provider. Not all providers support SCIM equally. Here is a breakdown by provider. For a full explanation of how directory sync works, see Directory Sync (SCIM) with MarketScale.
Provider | SCIM Support |
Microsoft Entra ID (Azure AD) | Yes |
Okta | Yes |
Google Workspace | Yes (via Google Cloud Directory) |
OneLogin | Yes |
JumpCloud | Yes |
PingOne | Yes |
CyberArk | Limited |
Directory sync is optional and can be configured during the same setup session as SSO.
Need Help?
If you are unsure whether your identity provider is compatible, reach out to us and let us know which provider you use. We can confirm compatibility and walk you through any provider-specific considerations before you begin setup.
Related:
