Log in Get Started

Connecting single sign-on (SSO) for your organization

SSO lets your team sign in through your company's identity provider (Okta, Azure AD, Google Workspace, and others) instead of a separate password. Configure it from your organization's SSO settings, choosing either SAML or OpenID Connect depending on what your identity provider supports.

For SAML, enter your identity provider's Entity ID, Sign-On URL, and X.509 certificate. For OpenID Connect, enter just the issuer URL, client ID, and client secret - we look up the rest of the configuration automatically.

Once enabled, team members can sign in either by visiting your organization's dedicated SSO link, or - if you've added and verified your company's email domain under Verified Domains - simply by entering their work email on the main login page, which routes them to the right identity provider automatically.

More in Security & Integrations

Setting up two-factor authentication (MFA) Provisioning users automatically with SCIM Using the API and webhooks