Skip to main content
If your preferred identity provider doesn’t have a pre-built integration with Lusha, you can use a custom SAML (Security Assertion Markup Language) connection to establish the link between the two systems. SAML is a standard for exchanging authentication and authorization data.
Only users with Admin or Manager roles can set up a custom SAML connection.

Configure your identity provider

Step 1: Gather data

  1. SSO post-backup URL: https://dashboard-services.lusha.com/v2/sso-saml (also known as the Assertion Consumer Service URL)
  2. Entity ID: https://dashboard-services.lusha.com/v2/sso-saml
  3. Your identity provider must ensure that a user is both authenticated and authorized before sending an assertion. If a user is not authorized, assertions should not be sent, and it is recommended that your identity provider redirects them to an HTTP 403 page.

Step 2: Configure attributes in IDP response

The following attributes should be included in the IDP response:
  • NameID (Required)
  • Email Attribute (Required)
  • First Name Attribute (Required)
  • Last Name Attribute (Required)
NameID (Required)
Email Attribute (Required)
First Name Attribute (Required)
Last Name Attribute (Required)

Step 3: Certificates

Public Certificate: Lusha requires that the SAML response be signed, and you will need to paste a valid X.509 .pem Certificate to verify your identity. This certificate is different from your SSL certificate.

Enable SAML SSO in Lusha

Once you have configured your identity provider, you can enable SAML in Lusha. Copy the XML file, go to Account Settings, paste the file under the “Custom SAML 2.0” section, and click Test SSO. Lusha runs a real sign-in against the metadata you provided and only shows SSO test passed once it actually works - nothing is enforced until you connect. Once the test passes, click Connect.
Lusha Custom SAML 2.0 section with Test SSO button
If you want to connect Azure or Okta to Lusha, refer to the Set up SSO (single sign-on) article.

Google SAML configuration

1

Open the Google Admin console

Go to the Google Admin console.
2

Add a custom SAML app

On the left sidebar, go to Apps → Web and mobile apps. Click the Add app dropdown → Add custom SAML app.
Google Admin console Add custom SAML app menu
3

Name the app

Under App details, name the app (for example: “Lusha saml”). The description is optional. Click Continue.
Google SAML app details form
4

Download the IDP metadata

Google identity provider details (IDP) - download the IDP metadata; you’ll need it later. Click Continue.
Google identity provider details with IDP metadata download link
5

Enter service provider details

Enter Service provider details - ACS URL and Entity ID: https://dashboard-services.lusha.com/v2/sso-saml. Change Name ID format to: EMAIL. Click Continue.
Google SAML service provider details form
6

Configure attribute mapping

Click Add mapping to add value for SAML response (click 3 times), then use the following attributes and values:Click Finish.
Google SAML attribute mapping configuration
7

Open the Lusha app in Google

You should then be able to see the app on the Web and mobile apps page. Click the Lusha app.
Lusha app listed in Google Web and mobile apps
8

Open user access settings

Click the User Access box (click the box itself - not “View details” or “Learn more”):
User Access box for the Lusha app in Google Admin console
9

Turn on the service and save

Change service status to ON. Click Save.
Service status toggle set to ON for the Lusha SAML app
10

Enable Custom SAML 2.0 in Lusha

Go to Account Settings on your Lusha account and enable SAML by clicking Custom SAML 2.0.
11

Copy the IDP metadata

Copy the entire content of the IDP file you downloaded earlier.
12

Paste the metadata and connect

Paste it into the custom SAML box. Click Connect.
Lusha Custom SAML 2.0 box with pasted IDP metadata
13

Grant access to your users

Go back to the Google Admin console → Apps → Web and mobile apps → Lusha → User Access - View Details. Grant access to all users in your Lusha account.
Done! All users should be able to connect via SSO.