SSO configuration guide
Configure single sign-on so your team can log in with your existing identity provider.
Was this helpful?
Configure single sign-on so your team can log in with your existing identity provider.
Single sign-on (SSO) lets your team authenticate using your existing identity provider (IdP) rather than a separate password. SSO is available on Business and Enterprise plans.
We support any SAML 2.0-compatible identity provider, including most enterprise IdPs. Check your provider's documentation for instructions on creating a SAML application.
In your identity provider's admin console, create a new SAML application. You'll need the following values from our settings page:
ACS URL (also called the Reply URL or Callback URL)
Entity ID (also called the Audience URI)
These are available under Settings → Security → SSO.
Make sure you can log in via SSO before enabling enforcement. If SSO breaks after enforcement is on, contact support — we can disable it for you from the backend.
With SCIM provisioning enabled, users are automatically added to or removed from your workspace when you add or remove them in your IdP. SCIM setup is available under Settings → Security → SCIM.
Was this helpful?
Was this helpful?