SSO, or Single Sign-On, is an authentication method that allows users to log in once and gain access to multiple applications or services without needing to authenticate again for each one. It simplifies the login process, improves security, and enhances the user experience.
Mapon offers Single Sign-On (SSO) functionality, enabling seamless and secure access for your users through their existing identity provider.
We support the SAML 2.0 protocol, ensuring compatibility with a wide range of identity provider platforms, such as Microsoft Entra ID.
📘 SAML SSO is available for Web platform and Driver mobile application (iOS, Android).
Full process flow chart
Set up steps
1. Create "Microsoft Entra ID" account
Go to the link below, select a plan according to your needs and create an account:
2. Create an Application
On your account, go to Microsoft Entra ID section.
Select "Enterprise Applications" section, click on + Add button, select Enterprise application option.
In the Microsoft Entra App Gallery, click + Create your own application and fill in your Application's name.
Select the option "Integrate any other application you don't find in the gallery (Non-gallery)" and click the Create button.
3. SAML configuration
Contact your client project manager, with reference to this section of these instructions.
🔔Your client project manager will initiate a request to our development team and will provide you with Entity ID and Reply URL shortly.
After that, in your newly created application, select the "Single sign-on" section from the menu on the left, and select SAML.
Click Edit (in the Basic SAML Configuration section).
Fill out the Entity ID and Reply URL with the URL we provided to you.
Click the Save button.
4. Attributes & Claims + Properties
During sign-in, claims send user information to the application.
Claim values come from the user's properties in Microsoft Entra ID.
You may choose any property from the user profile as a claim's value source, but ensure that the claim names match.
Attributes & Claims
Claims can be edited in the "Attributes & Claims" section:
Claim | Possible values, description |
|
used as the unique identifier for users in our system. | required | |
firstname | used when creating a new user/driver account. | required |
lastname | used when creating a new user/driver account. | required |
create_user
| Web platform user creation.
|
optional |
create_driver | Triggers Driver app driver creation.
|
optional |
vehicle_group | Value should correspond to some vehicle group ID in our system and after driver creation this driver will have access to the vehicles that are in this group. Example: 68889
Find vehicle group IDs in:
|
optional |
driver_id | This is driver's identifier, which will be saved in IButton ID field in Driver's profile.
|
optional |
User Properties
User properties are visible in the "Users and groups" section.
When adding users in Microsoft Azure, you need to choose and fill in the relevant properties.
5. Download and send "Metadata XML"
After completing all configuration steps above, download the Federation Metadata XML file and send it to us.
✅ We will then set up the application's SSO for your company on our side and notify you.
Additional Information
About driver creation (Driver App)
If you want to create drivers automatically (claim: create_driver = 1), it is mandatory to specify also vehicle_group. If vehicle_group is not specified for a new driver, driver account will not be created.
If you want to create an empty driver account (account that does not have access to any vehicles), use vehicle_group = 0.
SSO Login Flow Example (Driver App)
The driver logs in using SSO, passing the following claims:
firstname
lastname
create_driver = 1
vehicle_group = 11890
driver_id = 12345678
If the user does not already exist in our system, a new driver account is created.
In the Driver app, the system automatically allows the user to access vehicles in the group specified by the vehicle_group claim.
The driver_id claim is used as a driver identifier and is saved in the IButton ID field in our system.
The driver is created and has access to the Driver mobile application.
If driver has no access to web
If a driver does not have access to our web platform and it is necessary, it can be enabled in Driver profile manually by company's manager.









