Skip to Main Content

Share your product feedback

Status Future consideration
Categories Mobile
Created by Gavin Beattie
Created on Apr 30, 2026

Please add support for custom domains and SSO/SAML authentication in the mobile app.

What is the challenge?
  • The average user now spends around 2.5 hours per day on mobile devices, and increasingly expects core tools to be accessible in that context. While most to all of our ecosystem is already app-enabled (Allego, Highspot, Mediafly, Salesforce), Aha! Ideas remains the gap.

What is the impact?
  • Without SSO support and/or a way to access custom domains, it is difficult to position the product as a truly mobile-first tool. It also creates friction for clients and customers who are granted access to Aha! Ideas through portal-based access or separate authentication arrangements, effectively preventing usability and adoption on mobile.

Describe your idea.
  • From the mobile app login screen, enable a custom domain entry or selection prompt. Existing SaaS patterns (e.g., enterprise SSO-enabled apps above) can serve as reference implementations.

  • Once a domain is provided, mobile access should be routed accordingly, unblocking usage for enterprise and community scenarios (“big domain”/multi-tenant participation). This improves adoption, engagement, and overall platform reach.

  • As a stretch target, support multi-domain aggregation within a single app experience, similar to platforms like Discourse, allowing users to switch between different communities or organisational contexts seamlessly (e.g., enterprise vs. public/community spaces).

  • This also enables customers to extend access to their partners, clients, or downstream users, effectively acting as administrators of connected external audiences through their existing portal setup.

  • Current URL flow:
    https://secure.aha.io/session/new?set_global_timeout_session=true

  • Proposed flow:

  • User selects or enters custom domain

  • App maps to tenant context (e.g., requested_domain=company)

  • Optionally present a third option: “Use Community/External Credentials”

  • Route to appropriate authentication method:

    • SAML/OIDC via IdP (e.g., Microsoft Entra ID or other enterprise IdPs, e.g. Salesforce)

  • Redirect back to app with authentication token → sign in complete

  • Alternative domain-based entry:
    https://{company or organisation}.ideas.aha.io/portal_session/new

  • From the mobile app, provide:

  • Custom domain login option (primary e.g., Microsoft Entra)

  • Email-based domain detection (secondary)

  • Explicit enterprise IdP options (e.g. Saleforce, specified by {company or organisation})

  • Optional further third-party identity providers (e.g., Salesforce IdP or customer-managed IdP)

  • Authentication flow:

  • Select or enter domain → resolve tenant

  • Redirect to appropriate IdP login (SAML/OIDC)

  • Return to app with authorization token → complete sign-in

Use case.
  • I work for a partner of a large global organisation that also has multiple other partners. Both partner and wider community users access the global community via either Partner Community or Smart Community links and associated credentials.

  • Once inside the community, the platform (Salesforce) provides an IdP-based link to Aha! Ideas.

  • Applied to the mobile app using a new custom domain (or similar configuration), users log in to the client portal, via the mobile app, and the same redirection available in the desktop application logs them in. Users across the wider community can then access and review ideas as easily as checking their email.

  • Joining the dots: https://hexagonali.ideas.aha.io/ideas/DS-I-59

  • Attach files