Back to category

Enterprise SSO (SAML & OIDC)

Configure Single Sign-On for your organization using SAML 2.0 or OpenID Connect identity providers.

What You Can Do

  • Connect your corporate identity provider via OIDC (Azure AD, Okta, Google Workspace) or SAML 2.0.
  • Set up email-domain matching so team members are automatically redirected to your IdP on login.
  • New team members signing in via SSO for the first time are automatically added to your organization as Viewers.
  • IdP certificates and secrets are encrypted at rest and never stored in plain text.

Setup Notes

  • SSO is available on the Enterprise plan. Configure it under Settings → SSO.
  • For OIDC: provide the Issuer URL, Client ID, and Client Secret from your identity provider.
  • For SAML: provide the IdP login URL and certificate. An SP Entity ID is optional.
  • Team members who sign in via SSO for the first time are automatically added with the Viewer role.

Related Features