Go to the Addons tab and enable the SAML2 Web App toggle.
On the Settings tab, set the Application Callback URL to the ACS URL for your organization from the Settings page in the Single Sign-On section in Heroku.
Paste the following code into the Settings text box and click Debug.
The `audience` parameter is the **Heroku Entity ID** from the Settings page in Heroku. It will be formatted like this: `https://sso.heroku.com/saml/{yourHerokuOrg}.`5. Scroll to the bottom of the page and click **Enable**.6. On the **Usage** tab, locate **Identity Provider Metadata**, and click **Download** to download the metadata file. You'll need this when you configure Auth0 as the identity provider in Heroku. <Frame></Frame>## Configure SAML SSO in HerokuIn Heroku, on the Settings page in the <Tooltip tip="Single Sign-On (SSO): Service that, after a user logs into one applicaton, automatically logs that user in to other applications.">Single Sign-On</Tooltip> section, click **Upload Metadata** and select the file containing the **<Tooltip tip="Identity Provider (IdP): Service that stores and manages digital identities.">Identity Provider</Tooltip> Metadata** you downloaded in the previous step.