Authentication and Single Sign-On (SSO)

In addition to signing in with a username and password, Trakstar Perform can be configured to authenticate users through Single Sign-On (SSO) using SAML or LDAP.

Note: If your organization uses Mitratech HQ, refer to the Mitratech HQ documentation for authentication and login instructions.

Single Sign-On is an advanced Trakstar Perform feature. If your organization is interested in enabling SSO, contact perform@trakstar.com.

Administrators are responsible for configuring SSO integrations. If someone needs access to configure or manage SSO without broader administrative permissions, assign them the Integrations Admin role.


SAML

Security Assertion Markup Language (SAML) is an open standard that enables secure authentication between your organization's identity provider and Trakstar Perform.

After users authenticate with their organization's identity provider, they can access Trakstar Perform without entering a separate username and password.

Trakstar Perform supports integration with any SAML 2.0 identity provider, including:

  • OneLogin
  • Okta
  • Ping Identity
  • Google Apps (Google Workspace)
  • Azure Active Directory
  • Active Directory Federation Services (AD FS)
  • Other SAML 2.0-compatible providers

For provider-specific setup instructions, see:

For more information on setting up SAML in general, see our support article on configuring SAML in Trakstar Perform.


LDAP

Lightweight Directory Access Protocol (LDAP) allows Trakstar Perform to authenticate users against your organization's existing directory service, such as Microsoft Active Directory.

When LDAP authentication is enabled, Trakstar Perform validates usernames and passwords against your LDAP server, helping keep user credentials synchronized.

For configuration details, see Configuring LDAP in Trakstar Perform.

Important: Because Trakstar Perform is a cloud-based application, its servers must be able to communicate with your organization's LDAP server.

If your LDAP server is protected by firewalls or other network security controls, your organization must allow connections from Trakstar Perform.

Trakstar Perform cannot connect through your organization's VPN or local network.

For assistance, contact integrations@trakstar.com.


Configure and Test Authentication

Administrators can configure and test both SAML and LDAP integrations before enabling them for the entire organization.

If your organization already has existing Trakstar Perform users, you can verify the authentication configuration before requiring all users to sign in using SSO.

Refer to the appropriate SAML or LDAP setup guide for detailed configuration instructions.

Note: If you have SSO enabled, we highly recommend editing the Welcome Email before sending it to your employees. Otherwise, it will include non-relevant information about their login name and password. You can learn more about editing the Welcome Email - and all emails! - here.  We suggest the following text:


Hello {{recipient_first_name}},

Your Trakstar Perform account has been created or updated. Single Sign-On (SSO) has been enabled for your account.

Follow this link to get started now - you'll enter COMPANY NAME and then choose "Click here to log in with your SSO provider": {{login_link}} Thanks,

COMPANY NAME HR Team

Still need help? Contact Us Contact Us