Integration: Setting up SSO within Trakstar Hire
Single Sign-On (SSO) allows users to access Trakstar Hire using their organization's existing identity provider (IdP) credentials instead of managing a separate username and password.
Trakstar Hire supports SAML 2.0 identity providers, allowing users to authenticate through their organization's SSO solution while maintaining secure, centralized access management.
Using Mitratech HQ?
If your organization uses Mitratech HQ, refer to the Mitratech HQ-specific SSO documentation instead of this guide.
Before You Begin
To complete the setup, you'll need:
- A Super Admin account in Trakstar Hire.
- Administrative access to your organization's SAML 2.0 identity provider (IdP).
These permissions may belong to the same person or different administrators. If different teams manage Hire and your identity provider, work together to complete the configuration.
Step 1: Locate Your Trakstar Hire SAML Settings
- Sign in to Trakstar Hire as a Super Admin.
-
Navigate to Settings > Company Settings > SSO.

- Locate the following values:
- Single Sign-On / ACS (Consumer) URL
-
Issuer / Audience URI

You'll use these values when configuring your identity provider.
Step 2: Configure Your Identity Provider (IdP)
In your SAML 2.0 identity provider:
- Create a new SAML 2.0 application for Trakstar Hire.
- Configure the application using the following values from Trakstar Hire:
- Single Sign-On (ACS) URL
-
Audience URI (Issuer)

- Configure the application with:
- Application username: Email
- NameID format: Email address
- Assign the application to the users or groups who should have access to Trakstar Hire.
-
Copy the Identity Provider Metadata URL from your identity provider.

Note: Configuration steps vary by identity provider (such as Okta, Microsoft Entra ID, OneLogin, or others). Refer to your identity provider's documentation if you need assistance creating a SAML application.
Step 3: Connect Your Identity Provider to Trakstar Hire
- Return to Settings > Company Settings > SSO in Trakstar Hire.
-
Enable SAML.

-
Paste your Identity Provider Metadata URL into the Metadata URL field.

- Click Save.
Your SSO integration is now configured.
Important Information
Keep the following behavior in mind after enabling SSO.
User Accounts Must Already Exist
Enabling SSO does not automatically create user accounts.
Each user must already have an active account in Trakstar Hire before they can authenticate through your identity provider. SSO only changes how users sign in.
Login Experience
After SSO is enabled:
- Users launching Trakstar Hire from their identity provider are automatically signed in.
- Users opening links from Trakstar Hire emails are redirected to their identity provider for authentication before accessing Hire.
- Users can no longer sign in through the standard login page at hire.trakstar.com.
- Users should instead:
- Launch Trakstar Hire from their identity provider, or
- Use their organization's account-specific login URL:
https://{clientname}.hire.trakstar.com/accounts/login
Replace {clientname} with your organization's Trakstar Hire account name.
Chrome Extension
If you use the Trakstar Hire Chrome extension to import candidate profiles:
- Sign in to Trakstar Hire using SSO before using the extension.
- The Chrome extension itself does not support signing in through SSO.
Google SSO
Google Workspace cannot be used as the identity provider for this integration.
Trakstar Hire requires an Identity Provider Metadata URL for SAML configuration, and Google does not provide the required metadata URL for this implementation.
If you need additional assistance configuring SSO, contact the Trakstar Hire Support team.





