Private pages & SSO
Restrict who can view a status page with a shared password, one-time email links, or single sign-on through OpenID Connect or SAML 2.0.
By default a status page is public: anyone with the link can see it. For internal or customer-specific pages, you can require a password, or require visitors to sign in with your identity provider or a one-time email link. Private pages are hidden from search engines and have no public badge or feed.
Access modes#
Set who can view a page in the Access section of the page editor (Status pages in the sidebar, then click a page), under Who can view this page. Only the workspace owner can change access settings or sign visitors out; other members see the settings read-only.
| Mode | How visitors get in | Plans |
|---|---|---|
| Public | Anyone with the link can see the page. | All plans |
| Password protected | Visitors enter a password you share with them. | Growth and Pro |
| Single sign-on | Visitors sign in with your identity provider (OIDC or SAML) or a one-time link sent to an allowed email address. | Pro |
Access only applies to a published page. An unpublished page shows "not found" to everyone, whatever its access mode.
When you switch a page from public to a protected mode, you're asked to confirm, because:
- Visitors have to sign in to see it.
- The status badge and the Atom/RSS feed stop working.
- Search engines are asked not to index it.
Any change to the mode, the password or the sign-in settings signs every current visitor out.
Password-protected pages#
- In Access, select Password protected.
- Enter a Password of at least 8 characters (up to 128).
- Click Save access and confirm.
Share the password only with people who should see the page. To change it later, enter a New password; leave the field blank to keep the current one. Changing the password signs everyone out.
Visitors see a sign-in screen with your page title, logo and accent colour, and "This status page is private". They enter the password and click View status page. After signing in, they stay signed in for 7 days in that browser.
To stop guessing, a visitor's IP address can make only a limited number of password attempts in a short period. After that they see "Too many attempts. Please wait a few minutes and try again."
Single sign-on pages#
On Pro, Single sign-on lets visitors sign in instead of sharing a password. You can turn on any combination of three sign-in methods, and you control which people are allowed.
Allowed people#
| Field | What it does | Limits |
|---|---|---|
| Allowed email domains | Anyone with an email address at these domains may view the page, for example acme.com. Separate entries with commas, spaces or new lines. Domains must match exactly: subdomains are not included automatically. | Up to 50 domains |
| Allowed email addresses | Individual people outside those domains, for example a partner's address. | Up to 500 addresses |
These lists apply to every sign-in method, unless you tick Allow every user this provider signs in for OIDC or SAML.
One-time email link#
The simplest option: no identity provider needed.
- Select Single sign-on.
- Fill in Allowed email domains and/or Allowed email addresses.
- Tick One-time email link.
- Click Save access and confirm.
Visitors enter their Work email and click Email me a sign-in link. If the address is allowed, they get an email with a sign-in link that expires in 15 minutes and works once. The page always answers "If this address can view the page, a sign-in link is on its way", so it can't be used to find out which addresses are allowed.
If you remove someone from the allowed lists, links already sent to them stop working.
OpenID Connect (OIDC)#
Use this with Okta, Google Workspace, Microsoft Entra ID, Auth0 or any other OpenID Connect provider.
- Select Single sign-on and tick OpenID Connect.
- Copy the Redirect URI to register. It looks like
https://app.sutramx.com/status/<slug>/access/oidc/callback, or uses your custom domain if the page has one. - In your identity provider, create a web application (a confidential client using the authorization code flow) and register that redirect URI.
- Back in SutramX, enter the Issuer URL (for example
https://acme.okta.com), the Client ID and the Client secret. - Add allowed domains or addresses, or tick Allow every user this provider signs in, regardless of email.
- Click Save access and confirm.
| Field | What it does | Limits |
|---|---|---|
| Issuer URL | Your provider's issuer. SutramX reads its OpenID configuration from it when you save, so a typo is caught immediately. | Must be an https:// URL |
| Client ID | The client ID of the application you created. | Required |
| Client secret | The client secret. It is stored encrypted and never shown again; leave the field blank to keep the stored one. | Required |
| Allow every user this provider signs in | Lets anyone your provider authenticates view the page, regardless of email. Only use it if the application is assigned to just your people. | Off |
SutramX requests the openid, email and profile scopes and uses PKCE. Visitors are matched by the email address in their ID token. If the provider says the email is not verified, the visitor is only let in when Allow every user is on.
SAML 2.0#
- Select Single sign-on and tick SAML 2.0.
- In your identity provider, create a SAML application using the ACS URL (reply URL) and Entity ID (audience) shown in the panel, or click Download SP metadata and import the file.
- Back in SutramX, enter the Identity provider sign-in URL and paste the provider's Signing certificate.
- Add allowed domains or addresses, or tick Allow every user this provider signs in, regardless of email.
- Click Save access and confirm.
| Field | What it does | Limits |
|---|---|---|
| ACS URL (reply URL) | Where your provider sends the SAML response: https://app.sutramx.com/status/<slug>/access/saml/acs, or your custom domain. | Shown in the panel |
| Entity ID (audience) | Identifies this status page to your provider: urn:sutramx:status-page:<page id>. | Shown in the panel |
| Identity provider sign-in URL | Your provider's SAML single sign-on URL. | Must be an https:// URL |
| Identity provider entity ID | Your provider's issuer. | Optional |
| Signing certificate | Your provider's signing certificate in PEM format, starting with -----BEGIN CERTIFICATE-----. | Required |
SutramX asks for an email-address NameID. It reads the visitor's email from the email or mail attribute, the standard email address claims, or the NameID.
How visitors sign in#
Visitors to an SSO page see "This status page is private" and "Sign in to view it.", followed by the methods you turned on: Sign in with single sign-on (OIDC), Sign in with SAML, and the Work email field with Email me a sign-in link. After signing in with SSO or an email link, they stay signed in for 12 hours in that browser.
Signed-in visitors see "Signed in as" their email at the top of the page, with a Sign out button.
Sign everyone out#
To end every visitor session without changing any settings, click Sign out all visitors in Access and confirm. Everyone has to sign in again.
What changes on a private page#
| Feature | On a private page |
|---|---|
| Status badge and Atom/RSS feed | Turned off: they return "not found". The Share & embed section says so. |
| Search engines | Asked not to index the page. |
| Email subscriptions | Only signed-in visitors can subscribe. Confirmed subscribers still get incident emails. |
| Before sign-in | Visitors see only the page title, logo and accent colour. |
If your plan changes#
If your workspace moves to a plan that no longer includes the page's access mode, the page stays protected. The editor shows "Your plan no longer includes this option." You can switch it to Public at any time; that never needs a plan.
Troubleshooting#
| Message | What to do |
|---|---|
| "Turn on at least one sign-in method" | Tick one-time email link, OpenID Connect or SAML 2.0. |
| "Email sign-in needs at least one allowed domain or email address" | Add allowed domains or addresses. |
| "Add allowed domains or emails, or allow every user of the OIDC provider" | Add allowed people, or tick Allow every user. The same applies to SAML. |
| "OIDC issuer must be an https:// URL" | Enter the issuer exactly as your provider documents it. |
| "Your account does not have access to this status page." | The visitor's email isn't on the allowed lists, or the provider didn't send a verified email. |
| "This sign-in link is invalid or has expired." | Email links expire after 15 minutes and work once. Request a new one. |
| "This sign-in attempt expired. Please start again." | The visitor took too long at the identity provider. Start again from the page. |
| Visitors are signed out unexpectedly | Someone changed the access settings or clicked Sign out all visitors. |
Related
- Status pages overview
- Branding & custom domains
- Subscribers & updates
- Plans & limits
- Features: Public Status Pages
- Guides: Status Page Best Practices and Incident Response Basics
- Free tools: Incident Message Generator
- Use cases: Monitoring for SaaS Platforms
- More from SutramX: Status Page Features
Last updated . Something unclear or missing on this page? Tell us at support@sutramx.com.