Engels: SSO (Single Sign-On), work directly from your ATS
• ATS connector module 30 Jul 2026 by Nick Broekman

A recruiter has a vacancy open in the ATS and wants to promote it. In practice that means: a second tab, a second login screen, a password nobody remembers, and then finding that same vacancy all over again. That is exactly the moment half of them give up — and the vacancy stays invisible to the candidates you are looking for.

SSO (single sign-on) removes that hurdle. Your colleague signs in to your ATS — that is all. When they click through from a vacancy to Booston, they are already signed in and land straight on that vacancy. The end goal: every recruiter can promote their own vacancy from the system they already work in, without a second password and without waiting for an administrator.

This article goes into depth: what SSO actually does, how the two variants work, which ATSs support it, how Booston decides which account a colleague is linked to, what stays in your hands and where you end up when you click through. The settings you manage yourself live under Settings → Users & Permissions.

Before you start

  • You need the Manager role to manage users and to see which accounts came in through SSO.
  • Your ATS has to be connected to Booston. SSO builds on top of that connection: the vacancies come from your ATS, and so does the login.
  • SSO is built per ATS and switched on per environment. Booston sets that up together with you and your ATS vendor; it is not a switch you flip yourself.
  • Your Booston environment needs its own web address. Booston arranges that when your environment is set up.

What SSO actually does

SSO literally means: sign in once, get into several systems. At Booston that single sign-in moment is your ATS. Your ATS is the front door; Booston trusts that this door let the right person in and then creates a session of its own.

Under the hood that happens in three steps, every single time:

  1. Your ATS confirms who you are and passes that confirmation to Booston, digitally signed.
  2. Booston verifies that signature directly with the identity servers of your ATS vendor, and checks whether the ATS environment the confirmation came from really is linked to your Booston environment. If anything does not add up, it stops there.
  3. Booston finds or creates the matching user, checks that the user is active and prepares a secure session.

Just as important is what SSO does not do:

  • Booston never receives, sees or stores your ATS password. No password is synchronised.
  • SSO does not replace your Booston account. A user is simply created in Users & Permissions, with a role and permissions — exactly like an account you create yourself.
  • SSO is not a connection to Microsoft Entra ID or Google Workspace. Today Booston connects to your ATS, not directly to your corporate account. If you already sign in to your ATS with Microsoft or Google, that carries over indirectly: your ATS handles that step and Booston trusts the outcome.

What SSO gives you

The gain is not in the login screen itself, but in what actually happens after it.

  • No second password. No "forgot password" on the day a campaign has to go live, and no password policy to enforce in two places.
  • Recruiters work where they already are. With a tab integration they do not even leave their ATS. That saves not one click, but a context switch.
  • From vacancy to campaign in one click. You do not land on a dashboard where you have to look the vacancy up again — you land on that vacancy.
  • No double data entry. If the vacancy does not exist in Booston yet, Booston imports it from your ATS while the screen loads. Nobody has to retype it.
  • Access follows your ATS. Anyone removed from your ATS can no longer get in through SSO. You manage access in one place instead of two.
  • More people actually use it. The hurdle determines adoption. Remove the hurdle and the recruiters who know the vacancy best start using the tool themselves — instead of one marketer doing everything for everyone.
  • You stay in control. The fact that your ATS recognises someone does not automatically mean they may work in Booston. One setting decides whether new SSO users can get started immediately or have to pass a Manager first.

Two flavours: a tab inside your ATS, or a click-through

SSO comes in two variants. The result is the same — you are signed in and on the right vacancy — but they differ in whether Booston opens inside your ATS screen or in a window of its own.

Variant What it looks like What the ATS administrator does
Booston as a tab in your ATS Booston opens inside your ATS itself, as a tab on the vacancy. You stay in the screen you know; the Booston features simply sit alongside the rest. Install or enable Booston once inside the ATS, for example through your ATS vendor's marketplace.
Clicking through from your ATS You click a button or link on a vacancy in your ATS. A Booston screen opens in which you are already signed in. Have the button set up by your ATS vendor, with the key that only your environment may use.

What happens in both cases when you click:

  • With a tab inside your ATS, Booston runs a short sign-in round with your ATS's identity server, invisible to you. Usually you notice nothing at all, because you are already signed in to your ATS. Booston then exchanges that confirmation for a session of its own on your Booston environment's web address.
  • With a click-through, your ATS asks Booston for a one-time sign-in link, using a key tied to your environment. That link is valid briefly and works exactly once. Your browser follows it and you are in.

Which ATSs support SSO

ATS Variant Status What you can do now
Carerix Booston as a tab in Carerix Live Install Booston from the Carerix marketplace. After that a Booston tab appears on a vacancy; one click and you are on that vacancy's Boost tab.
ForceFlow Clicking through from ForceFlow Live Click through to Booston from a vacancy in ForceFlow. You arrive signed in, on the right vacancy.
Easyflex Booston as a tab in Easyflex Being built, on the Easyflex side Easyflex is building the connection in their own system. As soon as it exists, we switch it on for your environment. Let us know if you want to be on the list.
Otys Booston as a tab in Otys Being built, on our side We are building this connection now. Coming shortly.

Other ATSs will follow; which ones depends on what customers ask for. Working with an ATS that is not listed yet and you want SSO? Let us know — that weighs in on the order.

Signing in for the first time: how Booston finds the right user

This is the part we get the most questions about, so here it is in detail. When someone comes in through SSO, Booston wants to link them to exactly one Booston user — and to the right one. That happens in this order:

  1. Has this ATS user been here before? Booston stores which SSO identity belongs to a user. If Booston recognises it, that is it: same user, same role, same vacancies and candidates as last time.
  2. If not: is there a user with this email address? Booston searches for the email address the ATS passes on. If there is a match and your ATS has confirmed that the address belongs to this person, Booston links the SSO identity to that existing account. Your colleague keeps their work, their role and their history.
  3. Still no match? Booston creates a new user, with the name and email address from your ATS and the role Manager.

Booston always guards three boundaries here, and they are deliberate:

  • Never link on an unconfirmed email address. If that were allowed, anyone who can change their own email address in the ATS could impersonate a colleague and take over their Booston account.
  • Never take over an account that is already tied to a different SSO identity. One account belongs to one person.
  • Never link to a Booston administration or system account. Those accounts sit outside the user overview and stay there.

If one of these three blocks the login, your colleague sees an error message instead of access. That is not a fault but a deliberate stop. Email support@booston.io in that case and we will work out which account should be linked.

Deciding who gets in

The fact that your ATS recognises someone does not mean you want them in Booston. That is what the iFrame / SSO user activation card on Settings → Users & Permissions is for, with the Auto-activate iFrame / SSO users switch.

Position What happens with a new SSO user When you want this
On The user is created active straight away and can get started immediately. There is no intermediate step. Everyone allowed to work in your ATS is allowed to work in Booston.
Off (default) The user is created inactive and sees the message User has been paused. Please contact a Booston manager. A Manager has to set them to active first. You want to decide per person who gets access, even if that person is known in the ATS.

If the setting is off and a colleague reports that SSO "does not work", usually nothing is broken: look them up in the overview and switch Status on. They will come straight in afterwards. If the setting is on, your user list grows along with your ATS — so review the overview now and then and set accounts you do not need to inactive.

What you see in the user overview

SSO users simply sit among the other accounts. You can change their role, link team members, complete their profile and set them to inactive — exactly as with a user you created yourself. How that works is covered in Users: granting access, choosing roles and signing in from your ATS.

Two things you may come across:

  • An email address that looks like carerix+…@booston.io. If the ATS could not pass on a usable address, Booston fills in an internal address temporarily so the user can still work. Replace it with the real address in the edit panel.
  • The Manager role on everyone. A new SSO user gets Manager by default. If you do not want that, set them to Recruiter after the first sign-in and link the right team members.

Where you land: the Boost tab of that one vacancy

When you click through from a vacancy in your ATS, Booston does not take you to the dashboard but to the Boost tab of exactly that vacancy. That is the difference between "I am signed in" and "I can do something".

What happens in those few seconds:

  1. Booston recognises which vacancy this is, from the number your ATS sends along.
  2. If that vacancy does not exist in Booston yet, Booston starts the import from your ATS while the screen is still loading. It is usually there by the time you look.
  3. You end up on that vacancy's Boost tab, across the full width of the screen — even when you are working inside a tab in your ATS.

If you click through without a vacancy attached, for example from a general menu item, you land on the vacancy overview and pick one there yourself.

The recruiter becomes the marketer: boosting at vacancy level

That Boost tab holds everything you can deploy for this one vacancy, side by side, in the same layout, with the same buttons:

  • Meta job ads — ads on Facebook and Instagram for this vacancy, with the audience and the budget you choose.
  • [Jobboard network](https://booston.io/blog/post/jobboard-network-module) — one budget that automatically shifts towards the job boards that deliver applications most cheaply for this vacancy.
  • Cost & Performance — what this vacancy costs and what it returns, over the period you choose.

That is the idea behind the whole integration. Not: the marketer runs campaigns for a list of vacancies they do not know. But: the recruiter who wrote the vacancy, who knows which candidate they are looking for and who is calling the hiring manager tomorrow, switches on the marketing themselves — from the screen they already work in, at the moment it matters. No ticket, no waiting, no separate tool.

That Boost tab is deliberately built to keep growing. Every channel and every smart feature that gets added comes back in exactly the same place: as a block at vacancy level, with the same statuses and the same buttons. Understand the tab once and you also understand the next block that appears on it. What is coming first is listed under Coming soon.

Working safely: sessions, signing out and multiple environments

  • Your session is valid for eight hours. After that you sign in again. Through your ATS you usually notice nothing: you click through and you are back in.
  • Your session is tied to your environment's web address. If you work with several Booston environments in one browser, they do not sign each other out.
  • Deactivating takes effect immediately. When a Manager sets a user to inactive, running sessions stop at once — even if someone is working in the screen at that moment.
  • Too many attempts in a row are briefly blocked. That is protection against abuse; after a minute you can continue.
  • Multiple environments? An environment switcher sits under the Booston logo for customers with more than one environment. Switching is a plain redirect: you sign in again in the other environment. SSO runs per environment, not across all your environments at once.

Switching SSO on for your environment

We switch it on together. This is how it runs:

  1. Tell Booston you want SSO, naming your ATS and the number of recruiters who will use it.
  2. Make sure the ATS connection is in place: vacancies from your ATS arrive in Booston. SSO builds on that.
  3. Have your ATS administrator install or enable Booston on the ATS side. With Carerix that runs through the marketplace; with ForceFlow your ATS vendor sets up the click-through button.
  4. Booston links your ATS environment to your Booston environment and switches SSO on. From that moment the button or the tab works.
  5. Decide whether Auto-activate iFrame / SSO users should be on. If you are not sure, start with off: then you decide per person who gets in.
  6. Let one recruiter test it: open a vacancy in your ATS, click through and check that you land on that vacancy's Boost tab.
  7. After the first week, review the user overview and set the roles properly. The default is Manager; for most recruiters Recruiter is a better fit.

What you cannot arrange yourself

A few things deliberately go through us: they affect access to your whole environment or the connection with an external party.

  • Creating or breaking the link between your ATS environment and your Booston environment — that is the basis every SSO login is checked against. Email support@booston.io.
  • Switching Auto-activate iFrame / SSO users on or off — the switch is visible but can only be changed by Booston. Email us the position you want.
  • Unlinking an SSO login from a user, or attaching it to a different account — this cannot be done from the dashboard, precisely because it concerns identity. Tell us which person and which account it is about.
  • Adding a new ATS to SSO — that is development work on our side and often on your ATS vendor's side too. Your request weighs in on the order.
  • Permanently deleting a user — irreversible, and it changes the owner of vacancies and content. How to request it is covered in the article about users and roles.

Solving problems

The message "User has been paused. Please contact a Booston manager."

The user is inactive. That is what a new SSO user sees as long as Auto-activate iFrame / SSO users is off. Find the colleague under Settings → Users & Permissions and switch Status on.

A message that your environment is not connected

The link between your ATS environment and your Booston environment has not been made yet, or it has been stopped. You cannot tell from the installation in your ATS: that can have succeeded perfectly well. Email support@booston.io with the name of your ATS environment.

You end up on a waiting screen saying your request is being processed

Your Booston environment has been created but not released yet. As soon as the environment is ready, the same button simply works. You do not have to install anything again.

You are signed in, but the vacancy is not there

The import from your ATS is still running. Refresh the screen after half a minute. If it stays away, check whether the vacancy in your ATS has the status Booston picks up, and whether it can be found in Booston's vacancy overview.

You land on the overview instead of on the vacancy

You clicked through from a screen without a vacancy, or in Carerix from a match instead of from the vacancy itself. Open the vacancy in your ATS and click the Booston tab there.

The tab inside your ATS stays empty

Usually the browser is blocking third-party cookies. Try a normal window without privacy mode, switch blocking extensions off, or ask your IT department to allow cookies from booston.io.

An error message about an email address or an already linked account

Booston is refusing the link on purpose: the address has not been confirmed by your ATS, or the account is already tied to a different SSO identity. Email support@booston.io with the colleague's name and email address.

The message that too many attempts have been made

Protection against abuse has briefly blocked signing in. Wait a minute and try again.

Frequently asked questions

Do we have to create all our recruiters in Booston up front?

No. Booston creates the user automatically on the first sign-in. If you want to decide who actually gets in, leave Auto-activate iFrame / SSO users off.

What happens when a colleague leaves?

Removing them from your ATS means they can no longer come in through SSO. Set their Booston user to inactive as well: running sessions then stop immediately and they cannot sign in directly either.

Can SSO users also sign in with a password?

Yes. As soon as an SSO user is active, an email goes out with which they set a password themselves. After that they can sign in both through your ATS and directly on Booston.

Which role does someone coming in through SSO get?

Manager by default. For most recruiters Recruiter is a better fit. You change the role in the user's edit panel.

Can we use SSO and regular sign-in side by side?

Yes. Both routes lead to the same account. Some customers let recruiters come in through the ATS and administrators sign in directly.

Can we connect Microsoft Entra ID or Google Workspace?

Not directly for now. Booston connects to your ATS. If you already use Microsoft or Google to sign in to your ATS, that applies to Booston indirectly. If you need this, let us know — it helps us decide what to build.

Do you see our ATS passwords?

No. Booston only receives a signed confirmation from your ATS that this person is signed in, plus their name and email address. Passwords are not part of that.

How many people may come in through SSO?

Booston sets no limit. You decide with Auto-activate iFrame / SSO users and with the status per user who actually gets in.

Coming soon

  • SSO for Easyflex. Booston becomes a tab in Easyflex; Easyflex is building the connection on their side. As soon as this is live, we will update this article.
  • SSO for Otys. Booston becomes a tab in Otys. We are building this connection; it follows shortly.
  • AI as a third campaign type on the Boost tab. Alongside Meta job ads and Jobboard network, an AI block joins the same tab: run the audience analysis and have your job text optimised from the same place, with image and video as the next step.
  • A boost indicator in the vacancy overview. Per vacancy you will see at a glance how far it has been boosted, which channels are active and what has been spent — with one click through to the Boost tab.

Need help?

Are you stuck, or unsure whether SSO is available for your ATS yet? Email support@booston.io or call 085 0044 215 and mention:

  • the name of your environment and of your ATS;
  • what you want to achieve;
  • the message you see, if there is an error message.

Would you rather go through the settings together? Book a free 30-minute online demo — then we will go through it together. Job Done!

Latest News

Hot off the press!
blog-image
ATS Carerix
• ATS connector module 30 Jul 2026 by Niels Nieuwenbroek
blog-image
ATS Recruitee (Tellent)
• ATS connector module 30 Jul 2026 by Niels Nieuwenbroek
blog-image
ATS Integration
• Users, Settings & subscription 30 Jul 2026 by Thomas Evraets
blog-image
Attribute Management
• Users, Settings & subscription 30 Jul 2026 by Thomas Evraets

Want to know more? Book a free online demo. You could not ask for a better start.

We will walk you through the tool step by step and show you all the features that matter to you. Indeed, we do not need more than 30 minutes. It is that simple. Job done!

We use cookies on this website to facilitate its use, to improve performance and user experience and to increase the relevance of the offer. Click on agree to indicate that you agree with our privacy statement.