PitchBook

Getting started with single sign-on (SSO) - PitchBook

The PitchBook guide explains how to enable Single Sign-On (SSO) using SAML 2.0 to allow organizations to securely log in with corporate credentials across PitchBook’s web, mobile, Excel plugin, and Chrome extension, highlighting benefits like centralized authentication control, just-in-time user provisioning, and reduced password management, while advising collaboration with IT teams and PitchBook support to configure Service Provider and Identity Provider metadata through providers such as Okta or Microsoft Entra.

Overview

Enabling Single Sign-On (SSO) for PitchBook allows your organization to use a single set of corporate credentials to log in to multiple applications efficiently and securely. Benefits of utilizing SSO include:

  • Authentication Control: In an “SSO Mandatory” configuration, individual user authentication can be controlled directly by you, making it easier to manage user accounts, access, and permissions.
  • On-Demand Provisioning: Just-in-time (JIT) auto-provisioning allows PitchBook user accounts to be created automatically at login, reducing manual management of user access.
  • Company Credentialing: Using company authentication means fewer credentials to remember and maintain, reducing the likelihood of repeated and less secure passwords.

SSO relies on Service Provider (SP) metadata and Identity Provider (IdP) metadata to create an authenticated and secure login. Both SP and IdP requests are supported by the PitchBook SSO integration and can be configured using SAML 2.0 via your IdP provider (e.g., Okta, Microsoft Entra, OneLogin).

Authentication via SSO is supported across the PitchBook web platform, mobile application, Excel plugin, and Chrome extension.

Getting Started

The PitchBook technical support team assists with the setup and testing of your SSO integration. To initiate this request, contact the Support team at support@pitchbook.com. Once connected, the next step is creating a custom enterprise application on your IdP. PitchBook will provide a custom metadata file. Requesting PitchBook’s SP metadata is the first step to getting started.

Note: It is recommended to work with your company’s IT team for SSO implementation, as some steps require changes to your company’s identity provider.

IdP Configuration

After acquiring PitchBook’s SP metadata, follow these steps to create your custom enterprise application on your IdP provider, which will generate your IdP metadata. The exact steps may vary by provider, but the following configurations are required before testing your SSO connection with PitchBook:

  • Assertion Consumer Service (ACS) URL: See provided Metadata
  • SP Entity Id: See provided Metadata
  • SP Entity Name: PitchBook Platform
  • Assertion Signature Required: true
  • Binding: urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST
  • Name ID: email address (urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress) format that returns the email address used to log into PitchBook
  • Email Address attribute “email” required for configuration

If your Identity Provider supports importing Service Provider metadata via a link, you can import and parse necessary PitchBook metadata from the provided URL.

Once the application is created and configured, reply to your existing PitchBook customer support ticket with your IdP metadata, which should include your login URL and signing certificate, in one of the following formats:

  • Federation Metadata URL
  • XML Document

SP (PitchBook) Configuration

You will need to provide your Identity provider metadata, including the login URL and signing certificate, to PitchBook in one of the following formats:

  • Federation Metadata URL
  • XML Document

Also provide a list of all email domains that will be used for SSO.

Sample Azure AD Attribute Configuration

The following is an illustrative example of the Attributes & Claims configuration for Azure Entra ID SSO with JIT Auto-Provisioning enabled.

Details for attribute configuration are referenced but not included in this text extract.

FAQs

Can I still access PitchBook with my regular login?

No, users cannot use their original login methods once SSO is fully set up.

How do I access PitchBook through SSO?

PitchBook supports both SP-initiated and IdP-initiated SSO. For SP-initiated SSO, log in to PitchBook by navigating to https://my.pitchbook.com/ and clicking Sign in with SSO. A unique login link can be provided after SSO is configured.

Does PitchBook support SCIM for user provisioning for SSO?

At this time, PitchBook is not compatible with SCIM. However, just-in-time (JIT) auto-provisioning is supported as an optional feature for firm-wide licenses.