Single sign-on (SSO)
Let your team sign in with your identity provider: Okta, Microsoft Entra ID, Google Workspace, or any SAML 2.0 or OpenID Connect provider. Only admins can set it up.
SSO is included in the Scale plan only. On Free, Pro and Team, setting it up is refused.
Set it up
Go to Settings → Security and click Set up single sign-on.
1. Choose the protocol
Pick SAML 2.0 or OpenID Connect.
2. Give your identity provider our values
The page shows the values to copy into your identity provider (IdP).
- SAML 2.0: the ACS URL and the Entity ID / metadata URL. Send the user's email address as the NameID.
- OpenID Connect: the redirect URI. Create a web app with the authorization code flow and the
openid,emailandprofilescopes.
3. Give us your identity provider's details
- SAML 2.0: paste the IdP metadata XML, or click Use a URL instead and enter the IdP metadata URL.
- OpenID Connect: enter the Issuer or discovery URL, the Client ID and the Client secret.
Then test the connection.
4. Verify your email domains
- Click Add domain and enter your company's email domain.
- Add the TXT record shown at your DNS provider, then press Verify.
5. Choose a default role
New people who sign in through SSO join as Member, Observer or Admin; pick the default.
6. Require SSO (optional)
Turn on Require SSO so people from your domains must sign in through your IdP. Admins keep password and Google sign-in as a fallback, in case your IdP is down.
Provision people automatically
To have your IdP add and remove people and set their roles, set up SCIM provisioning.