Skip to content

SSO Configuration

Enterprise plans support Single Sign-On via SAML 2.0, OpenID Connect, or LDAP.

SAML Configuration

  1. Navigate to Settings > Security > SSO
  2. Select SAML as the provider
  3. Enter your IdP metadata URL or upload the metadata XML
  4. Configure attribute mappings for email, name, and groups
  5. Test the connection before enabling

OIDC Configuration

Enter your OIDC provider's client ID, client secret, and discovery URL.

LDAP Configuration

Enter your LDAP server URL, bind DN, and search base. Configure group-to-role mappings.

Domain Allowlisting

Restrict sign-in to specific email domains in Settings > Security > Allowed Domains.

On this page