Help center
Single sign-on & SCIM
Connect an OpenID Connect identity provider and provision members automatically (Enterprise).
Set up OIDC single sign-on
In Settings → Security & SSO, create an OIDC web application in your identity provider (Okta, Microsoft Entra ID, Google Workspace, Auth0 and others) with the redirect URL shown on that page. Then enter the issuer URL, client ID, client secret and your email domain.
- Verify your domain by adding the TXT record shown
- Run the connection test (discovery, endpoints and signing keys)
- Turn SSO on — people from your domain sign in at /sso
Just-in-time provisioning
With just-in-time provisioning on, the first SSO sign-in from your domain creates a membership with the default role you chose. Turn it off to allow only people you've added or provisioned via SCIM.
SCIM provisioning
Generate a SCIM token in Settings → Security & SSO and give your identity provider the SCIM base URL and token. Supported: listing and filtering users by userName, creating, updating (PATCH/PUT) and deleting users.
- Setting active to false deactivates the membership and signs the person out everywhere immediately
- Deleting a user removes their access; their contacts and cards stay with the workspace
- Only accounts on your verified domain can be provisioned
- The last owner can't be deprovisioned, so you can't lock yourself out