What is SAML SSO?
Single Sign-On (SSO) authentication using Security Assertion Markup Language (SAML) is a secure and straightforward login standard that enables users to authenticate once and gain access to associated websites or applications. SAML facilitates the exchange of security credentials between an identity provider and a service provider (Semrush), providing a reliable method of authenticating and authorizing users across different platforms, digital touchpoints, and devices.

SAML SSO vs. password-based authentication
- Higher security (no weak passwords; identity provider stores the login data)
- Easier maintenance (no need to reset passwords or create credentials for new users)
- Better user experience (no need to remember and type in credentials)
Supported features and limitations
Currently, Semrush utilizes SAML 2.0 and offers user creation, registration, and authorization features.
SSO is available to Guru and Business users.
Semrush SAML SSO Integration Steps
Note: Make sure your users are already registered on the Semrush platform before initiating the SAML SSO integration.
To enable SSO, contact our team via this form.
Step 1
The Semrush team provides you with the following configuration data:
- ACS URL/Reply URL: https://www.mtsemru.toolsnovintrend.ir/sso/saml/acs
- Metadata URL: https://www.mtsemru.toolsnovintrend.ir/sso/saml/metadata/
- Audience URI/Entity ID: https://sso.semrush.com
- Default Relay State: https://www.mtsemru.toolsnovintrend.ir/dashboard/
Note: Semrush uses NameID from SAML responses for authentication. Ensure that you configure this attribute with your identity provider.
Step 2
After configuring your SSO environment, you will need to:
- Download the SAML Signing Certificate
- Download the SAML Entity Metadata XML file
- Send both files along with your preferred allowlist, which may include authorization domain name(s), specific email addresses, or a combination of both, to the Semrush team.
Step 3
The Semrush team processes the data and confirms once the integration is complete.
Generally, it takes approximately 1 business day to complete the integration, depending on the Semrush team's workload. To expedite the process, please submit all necessary data on time and be prepared to provide additional information as needed.
Log in to Semrush via SAML SSO
Once the integration is done, there will be two options for your users to log in to Semrush via SAML SSO:
- Use the link https://www.mtsemru.toolsnovintrend.ir/login/saml/, which will redirect a user to your identity provider. Once they authenticate using their corporate credentials, they will be authorized and redirected to the Semrush interface.
- Alternatively, a user can open a list of applications registered on your identity provider and select Semrush to proceed to the Semrush interface.
Note: After the integration is complete, your users will still be able to use password-based authentication. Even if they log in via SAML SSO, the password option will remain available until you have fully tested the integration and explicitly request that Semrush disable password-based login.