Enterprise digital signage your IT team can sign off
Screens across many sites, many teams publishing to them, and an IT department that has to answer for all of it. ScreenTinker gives you single sign-on with your own identity provider, roles that match how you work, approvals before anything goes live, and a full activity log. Run it on our hosted service, or on your own servers with the same software, because it is open source.
Single sign-on with your identity provider
- SAML 2.0 and OpenID Connect, per organization. Okta, Microsoft Entra ID, ADFS, Google Workspace, OneLogin, PingFederate, JumpCloud and others. An organization admin sets it up in Settings → Single sign-on, with no restart and no help from us.
- DNS-verified domains. You prove each email domain with a TXT record. Your provider can only sign in addresses at domains you have verified, and a domain belongs to one organization.
- Require SSO. Turn it on and passwords and other sign-in methods are refused for everyone at your domains. Turning it off needs a platform administrator to approve it, so one compromised admin can’t quietly reopen password sign-in.
- Strict SAML checks. Every assertion must be signed, answer a sign-in we started in the same browser, come from your IdP, be addressed to us and be used only once.
- Two-factor authentication (TOTP, with recovery codes) for anyone not on SSO.
Roles, workspaces and head office control
- Organizations and workspaces. One organization can hold a workspace per site, region, client or department. Organization owners and admins run the organization; inside each workspace, people are admins, editors or viewers.
- Head office playlists. Head office publishes playlists that stores can’t change, decides where they play, and leaves local slots for each store’s own content. It can also run emergency alerts across the estate. All of it is enforced on the server.
- Approval before release. Turn on approvals for a workspace and nothing goes live until a reviewer approves the exact version. No self-approval.
- Version history. Every meaningful save of content, playlists, layouts, slides and widgets is kept, can be compared, and can be restored.
- Activity log. Who changed what, and when, including sign-ins, support sessions, room bookings and automation calls.
- Consent-gated support access. Our support can only look inside a self-hosted instance after an admin generates a single-use request code, for a limited window, and every step lands in your activity log.
Fleet operations at scale
- Device tags and dynamic groups. Tag screens by site, floor or type, and let groups fill themselves from rules. Playlists, schedules, triggers, emergency alerts and power schedules follow the group.
- Player updates in waves. A new Android, Raspberry Pi or Windows player goes to about 10% of screens first, then 50%, then everyone. If updated screens crash or go dark more than the rest, the rollout halts itself. Pi and Windows screens roll back automatically; Android can’t install an older version, so there a halt stops the spread until a fixed build ships.
- Offline alerts to your tools. Slack, Microsoft Teams, PagerDuty, email or a signed webhook, for the screens and groups you choose. PagerDuty incidents close themselves when a screen comes back.
- An open API and an MCP server. API tokens are bound to one workspace and one scope, and can never reach administration, billing or provisioning. AI assistants connect through the same API.
Your infrastructure, if you want it
- Hosted or self-hosted, same software. The hosted service and the open-source server run the same code, MIT licensed, so leaving the hosted service never means leaving the software.
- Your own storage. Keep media in Amazon S3, an S3-compatible store (MinIO, Ceph, R2, B2, Wasabi and others) or Azure Blob, per organization or per workspace, and move existing media across while screens keep playing.
- Scale-out replicas (self-hosted). Add read replicas near your operators and screens. Writes still go to one primary, and a replica is not a backup.
- Node mesh. One screen on a site downloads a video once and shares it with its neighbours over the LAN.
Set it up
- Start a trial, or install the server on your own infrastructure with the self-hosting guide.
- In Settings → Single sign-on → Add provider, choose SAML 2.0 and paste your IdP’s metadata, or enter your OIDC issuer and client.
- Publish the TXT record for each email domain and press Verify.
- Sign in through SSO once, then turn on Require single sign-on.
- Create workspaces, invite people with the right roles, and turn on approvals where you need them.
- The full walkthrough, with troubleshooting codes, is in the SSO setup guide. Approvals are covered in approvals and history, head office playlists in corporate playlists, and storage in the storage guide.
Limits, plainly
- No compliance certifications. ScreenTinker does not hold SOC 2, ISO 27001 or HIPAA attestations. If you need your data under your own controls and audits, self-host it: the server, database and media then live in your environment.
- SAML needs HTTPS, and IdP-initiated sign-in (starting from an app tile in your IdP portal) is refused. People start from the ScreenTinker sign-in page.
- Require SSO clears the passwords of members at your verified domains, and that can’t be undone without a reset.
- Microsoft multi-tenant sign-in isn’t supported for the instance-wide Microsoft provider. Each organization connects its own tenant.
- Scale-out has documented gaps, such as live view and playback history staying on the primary. Read the scale-out guide before planning on it.
Talk to us
Many organizations, volume pricing or a custom hosting arrangement? Use the Enterprise contact form on the pricing section and tell us about your deployment.
FAQ
Does ScreenTinker support SAML single sign-on?
Yes. Each organization can add its own SAML 2.0 or OpenID Connect provider, such as Okta, Entra ID, ADFS, Google Workspace or OneLogin, and verify its email domains with a DNS TXT record.
Can we force everyone to sign in with SSO?
Yes. Require single sign-on refuses passwords and other providers for everyone at your verified domains. Turning it off needs a platform administrator to approve it.
Is ScreenTinker SOC 2 or HIPAA certified?
No. It holds no compliance certifications. Organizations that need their data under their own controls can self-host it, so the server, database and media live in their own environment.
Can head office stop stores changing content?
Yes. Head office playlists can’t be changed by stores, and head office decides where they play. Stores fill only the local slots head office leaves them.
Is there an audit trail?
Yes. The activity log records changes, sign-ins, support sessions and automation calls, and version history keeps every meaningful save of content and playlists.
Can we run it on our own servers?
Yes. ScreenTinker is open source under the MIT licence, and the self-hosted server is the same software as the hosted service, with no device cap.
Prove it out before you roll it out
Start a 14-day Pro trial on hosted ScreenTinker: up to 15 screens, every feature, no credit card. Connect your identity provider on day one.
Or host it yourself, free and open source: self-hosting guide · GitHub