Requirements
- Identity provider account with access to the administrator console
- Grammarly Business, Grammarly Pro, or Grammarly for Education account with the admin role or a designated custom role
Instructions on adding Grammarly to different identity providers:
- Okta
- ClassLink
- Centrify
- Azure AD
- PingOne
- Auth0
- OneLogin
- ADFS
- CyberArk Identity
- Rippling
- QuickLaunch
- JumpCloud
If your identity provider is not on the list, you can still try to configure it for Grammarly using the following parameters:
- Single sign-on URL: https://sso.grammarly.com/saml/assertion
- Audience URI/SP Entity ID/Issuer: https://sso.grammarly.com/saml/metadata
- Name ID format: EmailAddress
- Name ID / Application Username / Unique Identifier: Email
-
Required attributes/claims:
- EmailAddress
- FirstName
- LastName
-
Optional attributes/claims:
- GrammarlyRole
- GrammarlyGroup
- CostCenter
- CommonName (instead of FirstName and LastName)
Note: The names of attributes/claims must follow the specified format. Alternative name spellings or FriendlyNames are not supported.
If present, the GrammarlyRole attribute assigns appropriate permission to the member. For more information about roles and permissions, see this article: Manage team member roles
The supported GrammarlyRole values are:
- ADMIN
- ACCOUNT_MANAGER
- INSTITUTION_USER
- Custom role name
Note: Custom roles are available only to Grammarly Enterprise customers.
If present, the GrammarlyGroupRoleGroupManager attribute assigns the appropriate permission to a team member. The value of the attribute should be the name of the group that the member is assigned to manage.
Note: Group manager permissions are available only to Grammarly Enterprise customers.
If present, the GrammarlyGroup attribute assigns the member to the corresponding group within Grammarly. For more information about groups, see this article: Organize team members into groups
If the CostCenter attribute is present, it will automatically assign the appropriate cost center to each member, which can then be viewed in the Grammarly admin panel. This option is available upon request for Grammarly Enterprise customers.
Grammarly SSO supports alternative attribute and claim names to be compliant with standards such as InCommon. Below is a list of alternative attributes/claims that can be used:
- EmailAddress: mail, urn:oid:0.9.2342.19200300.100.1.3
- CommonName: commonName, cn, urn:oid:2.5.4.3
- FirstName: givenName, urn:oid:2.5.4.42
-
LastName: surname, sn, urn:oid:2.5.4.4
After you have the Grammarly SAML app set up in your identity provider, please see the following article on how to enable SSO for your account: Set up SAML single sign-on