Available on: Professional, Enterprise | Role: Organization Owner only | Status: Generally Available
Overview
Enterprise SSO lets your organization use existing identity providers (Azure AD, Okta, Google Workspace, or custom SAML 2.0) for authentication. Users sign in with their corporate credentials instead of managing separate passwords.Available SSO Providers
| Provider | Protocol | Plans |
|---|---|---|
| Google OAuth | OAuth 2.0 | All plans |
| Microsoft OAuth | OAuth 2.0 | Professional+ |
| Azure AD (Entra ID) | SAML / OAuth | Professional+ |
| Google Workspace | SAML | Professional+ |
| Okta | SAML | Professional+ |
| Custom SAML 2.0 | SAML | Professional+ |
Setting Up SSO
Select a Provider
Choose the identity provider you want to configure. Each provider has its own setup requirements.
Configure the Connection
Enter the required details for your identity provider:
- Azure AD: Tenant ID, Client ID, Client Secret
- Okta: Okta domain, Client ID, Client Secret
- Google Workspace: Domain, Client ID
- Custom SAML: SAML Metadata URL or manual configuration
Test the Connection
Use the Test button to verify the SSO configuration works before enabling it for all users.
SSO User Behavior
- Auto-verification — SSO users are automatically verified (no email confirmation needed)
- Auto-provisioning — New users are created on first SSO sign-in
- Role assignment — New SSO users get the organization’s default role